Publish Advisories

GHSA-29vf-j74g-gmfc
GHSA-7pq2-85jv-r5mw
GHSA-86c6-5vcx-3893
GHSA-9fpq-xxr8-j37x
GHSA-gg89-f9mq-2rw9
GHSA-gq65-23cc-h5wp
GHSA-h9vj-4r4f-c87f
GHSA-pp2q-hf69-vw5g
GHSA-pw4c-h493-rxm2
GHSA-w439-f952-rj94
GHSA-w796-2gq9-7jm8
This commit is contained in:
advisory-database[bot]
2023-10-02 18:31:36 +00:00
parent 33324f81de
commit f7464eccd4
11 changed files with 62 additions and 16 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-29vf-j74g-gmfc",
"modified": "2023-09-27T21:30:31Z",
"modified": "2023-10-02T18:30:20Z",
"published": "2023-09-27T15:30:35Z",
"aliases": [
"CVE-2023-40044"
@@ -21,13 +21,33 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40044"
},
{
"type": "WEB",
"url": "https://attackerkb.com/topics/bn32f9sNax/cve-2023-40044"
},
{
"type": "WEB",
"url": "https://censys.com/cve-2023-40044/"
},
{
"type": "WEB",
"url": "https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023"
},
{
"type": "WEB",
"url": "https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-iis-http-modules-cve-2023-40044"
},
{
"type": "WEB",
"url": "https://www.progress.com/ws_ftp"
},
{
"type": "WEB",
"url": "https://www.rapid7.com/blog/post/2023/09/29/etr-critical-vulnerabilities-in-ws_ftp-server/"
},
{
"type": "WEB",
"url": "https://www.theregister.com/2023/10/02/ws_ftp_update/"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7pq2-85jv-r5mw",
"modified": "2023-09-28T00:30:21Z",
"modified": "2023-10-02T18:30:22Z",
"published": "2023-09-28T00:30:21Z",
"aliases": [
"CVE-2023-43233"
],
"details": "A stored cross-site scripting (XSS) vulnerability in the cms/content/edit component of YZNCMS v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-86c6-5vcx-3893",
"modified": "2023-09-28T00:30:21Z",
"modified": "2023-10-02T18:30:22Z",
"published": "2023-09-28T00:30:21Z",
"aliases": [
"CVE-2023-43314"
],
"details": "Buffer Overflow vulnerability in ZYXEL ZYXEL v.PMG2005-T20B allows a remote attacker to cause a denial of service via a crafted script to the uid parameter in the cgi-bin/login.asp component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"github_reviewed": false,
@@ -36,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-362"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gg89-f9mq-2rw9",
"modified": "2023-09-27T15:30:40Z",
"modified": "2023-10-02T18:30:21Z",
"published": "2023-09-27T15:30:40Z",
"aliases": [
"CVE-2023-5172"
],
"details": "A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 118.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": null,
"github_reviewed": false,
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-668",
"CWE-927"
],
"severity": null,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h9vj-4r4f-c87f",
"modified": "2023-09-27T15:30:38Z",
"modified": "2023-10-02T18:30:20Z",
"published": "2023-09-27T15:30:38Z",
"aliases": [
"CVE-2023-43154"
],
"details": "In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in \"isValidLogin()\" function during login attempt results in PHP type confusion vulnerability that leads to authentication bypass and takeover of the administrator account.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-843"
],
"severity": null,
"github_reviewed": false,
@@ -36,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-312"
],
"severity": null,
"github_reviewed": false,
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-668",
"CWE-927"
],
"severity": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w439-f952-rj94",
"modified": "2023-09-27T18:30:28Z",
"modified": "2023-10-02T18:30:21Z",
"published": "2023-09-27T18:30:28Z",
"aliases": [
"CVE-2023-43125"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42793"
},
{
"type": "WEB",
"url": "https://attackerkb.com/topics/1XEEEkGHzt/cve-2023-42793"
},
{
"type": "WEB",
"url": "https://blog.jetbrains.com/teamcity/2023/09/cve-2023-42793-vulnerability-post-mortem/"
@@ -29,6 +33,14 @@
"type": "WEB",
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
},
{
"type": "WEB",
"url": "https://www.rapid7.com/blog/post/2023/09/25/etr-cve-2023-42793-critical-authentication-bypass-in-jetbrains-teamcity-ci-cd-servers/"
},
{
"type": "WEB",
"url": "https://www.securityweek.com/recently-patched-teamcity-vulnerability-exploited-to-hack-servers/"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/174860/JetBrains-TeamCity-Unauthenticated-Remote-Code-Execution.html"