Publish Advisories

GHSA-w5vh-2923-gp5c
GHSA-f6rj-qrpf-jc34
GHSA-ppmf-rp3c-49x9
GHSA-445f-cm55-gq8v
GHSA-6grj-h983-99rg
GHSA-6pp8-37pj-mhcc
GHSA-78p2-p949-pjvr
GHSA-7j77-3p87-xr63
GHSA-8r5c-mgwc-qg49
GHSA-c5vx-x65g-94m5
GHSA-h7wp-7q3v-7m5w
GHSA-j2p7-j8v8-q5g2
GHSA-jjfr-pq2x-mf69
GHSA-qfm4-9qqj-3w82
GHSA-v576-wfmr-x3x7
GHSA-vh9j-8vw4-5hp6
GHSA-xc7v-9m4q-8q68
This commit is contained in:
advisory-database[bot]
2024-01-30 21:31:46 +00:00
parent db1e70bbdb
commit f807c95288
17 changed files with 156 additions and 50 deletions
@@ -29,6 +29,14 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2021/01/msg00022.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CALA5FTXIQBRRYUA2ZQNJXB6OQMAXEII/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LHXK6ICO5AYLGFK2TAX5MZKUXTUKWOJY/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CALA5FTXIQBRRYUA2ZQNJXB6OQMAXEII/"
@@ -136,6 +144,14 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2021/09/14/2"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/01/30/6"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/01/30/8"
}
],
"database_specific": {
@@ -32,6 +32,14 @@
{
"type": "WEB",
"url": "https://sourceware.org/bugzilla/show_bug.cgi?id=29536"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/01/30/6"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/01/30/8"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ppmf-rp3c-49x9",
"modified": "2023-09-13T06:30:21Z",
"modified": "2024-01-30T21:30:28Z",
"published": "2023-09-12T00:30:26Z",
"aliases": [
"CVE-2023-40440"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40440"
},
{
"type": "WEB",
"url": "https://blog.aegrel.ee/apple-mail-smime.html"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213844"
@@ -30,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-09-12T00:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-445f-cm55-gq8v",
"modified": "2024-01-24T21:30:33Z",
"modified": "2024-01-30T21:30:29Z",
"published": "2024-01-24T21:30:33Z",
"aliases": [
"CVE-2024-22751"
],
"details": "D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T21:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6grj-h983-99rg",
"modified": "2024-01-23T21:30:21Z",
"modified": "2024-01-30T21:30:28Z",
"published": "2024-01-23T21:30:21Z",
"aliases": [
"CVE-2023-47199"
],
"details": "An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThis vulnerability is similar to, but not identical to, CVE-2023-47193.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-346"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-23T21:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6pp8-37pj-mhcc",
"modified": "2024-01-23T21:30:21Z",
"modified": "2024-01-30T21:30:28Z",
"published": "2024-01-23T21:30:21Z",
"aliases": [
"CVE-2023-52325"
],
"details": "A local file inclusion vulnerability in one of Trend Micro Apex Central's widgets could allow a remote attacker to execute arbitrary code on affected installations.\n\nPlease note: this vulnerability must be used in conjunction with another one to exploit an affected system. In addition, an attacker must first obtain a valid set of credentials on target system in order to exploit this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-23T21:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-78p2-p949-pjvr",
"modified": "2024-01-24T18:31:01Z",
"modified": "2024-01-30T21:30:28Z",
"published": "2024-01-24T18:31:01Z",
"aliases": [
"CVE-2023-52038"
],
"details": "An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T18:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7j77-3p87-xr63",
"modified": "2024-01-24T18:31:01Z",
"modified": "2024-01-30T21:30:28Z",
"published": "2024-01-24T18:31:01Z",
"aliases": [
"CVE-2023-52039"
],
"details": "An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T18:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8r5c-mgwc-qg49",
"modified": "2024-01-24T09:30:25Z",
"modified": "2024-01-30T21:30:28Z",
"published": "2024-01-24T09:30:25Z",
"aliases": [
"CVE-2023-51711"
],
"details": "An issue was discovered in Regify Regipay Client for Windows version 4.5.1.0 allows DLL hijacking: a user can trigger the execution of arbitrary code every time the product is executed.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-427"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T07:15:47Z"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h7wp-7q3v-7m5w",
"modified": "2024-01-30T21:30:29Z",
"published": "2024-01-30T21:30:29Z",
"aliases": [
"CVE-2023-5389"
],
"details": "\nAn attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion VirtualUOC and UOC . This exploit could be used to write a file that may result in unexpected behavior based on configuration changes or updating of files that could result in subsequent execution of a malicious application if triggered. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning. ",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5389"
},
{
"type": "WEB",
"url": "https://process.honeywell.com"
},
{
"type": "WEB",
"url": "https://www.honeywell.com/us/en/product-security"
}
],
"database_specific": {
"cwe_ids": [
"CWE-749"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-30T20:15:45Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j2p7-j8v8-q5g2",
"modified": "2024-01-24T18:31:01Z",
"modified": "2024-01-30T21:30:28Z",
"published": "2024-01-24T18:31:01Z",
"aliases": [
"CVE-2024-22725"
],
"details": "Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's error reporting.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T16:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jjfr-pq2x-mf69",
"modified": "2024-01-23T21:30:21Z",
"modified": "2024-01-30T21:30:28Z",
"published": "2024-01-23T21:30:21Z",
"aliases": [
"CVE-2023-52331"
],
"details": "A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central could allow an attacker to interact with internal or local services directly.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-23T21:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qfm4-9qqj-3w82",
"modified": "2024-01-24T18:31:01Z",
"modified": "2024-01-30T21:30:28Z",
"published": "2024-01-24T18:31:01Z",
"aliases": [
"CVE-2024-22651"
],
"details": "There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T16:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v576-wfmr-x3x7",
"modified": "2024-01-23T21:30:21Z",
"modified": "2024-01-30T21:30:28Z",
"published": "2024-01-23T21:30:21Z",
"aliases": [
"CVE-2023-52324"
],
"details": "An unrestricted file upload vulnerability in Trend Micro Apex Central could allow a remote attacker to create arbitrary files on affected installations.\n\nPlease note: although authentication is required to exploit this vulnerability, this vulnerability could be exploited when the attacker has any valid set of credentials. Also, this vulnerability could be potentially used in combination with another vulnerability to execute arbitrary code.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-23T21:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vh9j-8vw4-5hp6",
"modified": "2024-01-24T18:31:01Z",
"modified": "2024-01-30T21:30:28Z",
"published": "2024-01-24T18:31:01Z",
"aliases": [
"CVE-2023-52040"
],
"details": "An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T18:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xc7v-9m4q-8q68",
"modified": "2024-01-24T18:31:01Z",
"modified": "2024-01-30T21:30:29Z",
"published": "2024-01-24T18:31:01Z",
"aliases": [
"CVE-2024-22720"
],
"details": "Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T18:15:08Z"