diff --git a/advisories/unreviewed/2022/05/GHSA-w5vh-2923-gp5c/GHSA-w5vh-2923-gp5c.json b/advisories/unreviewed/2022/05/GHSA-w5vh-2923-gp5c/GHSA-w5vh-2923-gp5c.json index d088825e148..669148a8346 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5vh-2923-gp5c/GHSA-w5vh-2923-gp5c.json +++ b/advisories/unreviewed/2022/05/GHSA-w5vh-2923-gp5c/GHSA-w5vh-2923-gp5c.json @@ -29,6 +29,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2021/01/msg00022.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CALA5FTXIQBRRYUA2ZQNJXB6OQMAXEII/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LHXK6ICO5AYLGFK2TAX5MZKUXTUKWOJY/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CALA5FTXIQBRRYUA2ZQNJXB6OQMAXEII/" @@ -136,6 +144,14 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2021/09/14/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/30/6" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/30/8" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/09/GHSA-f6rj-qrpf-jc34/GHSA-f6rj-qrpf-jc34.json b/advisories/unreviewed/2022/09/GHSA-f6rj-qrpf-jc34/GHSA-f6rj-qrpf-jc34.json index d1f2be1e5e2..06b8cbcae26 100644 --- a/advisories/unreviewed/2022/09/GHSA-f6rj-qrpf-jc34/GHSA-f6rj-qrpf-jc34.json +++ b/advisories/unreviewed/2022/09/GHSA-f6rj-qrpf-jc34/GHSA-f6rj-qrpf-jc34.json @@ -32,6 +32,14 @@ { "type": "WEB", "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=29536" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/30/6" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/30/8" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-ppmf-rp3c-49x9/GHSA-ppmf-rp3c-49x9.json b/advisories/unreviewed/2023/09/GHSA-ppmf-rp3c-49x9/GHSA-ppmf-rp3c-49x9.json index a29e947085f..3fb9b046181 100644 --- a/advisories/unreviewed/2023/09/GHSA-ppmf-rp3c-49x9/GHSA-ppmf-rp3c-49x9.json +++ b/advisories/unreviewed/2023/09/GHSA-ppmf-rp3c-49x9/GHSA-ppmf-rp3c-49x9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ppmf-rp3c-49x9", - "modified": "2023-09-13T06:30:21Z", + "modified": "2024-01-30T21:30:28Z", "published": "2023-09-12T00:30:26Z", "aliases": [ "CVE-2023-40440" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40440" }, + { + "type": "WEB", + "url": "https://blog.aegrel.ee/apple-mail-smime.html" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT213844" @@ -30,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-09-12T00:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-445f-cm55-gq8v/GHSA-445f-cm55-gq8v.json b/advisories/unreviewed/2024/01/GHSA-445f-cm55-gq8v/GHSA-445f-cm55-gq8v.json index 909725e38ee..00c92459101 100644 --- a/advisories/unreviewed/2024/01/GHSA-445f-cm55-gq8v/GHSA-445f-cm55-gq8v.json +++ b/advisories/unreviewed/2024/01/GHSA-445f-cm55-gq8v/GHSA-445f-cm55-gq8v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-445f-cm55-gq8v", - "modified": "2024-01-24T21:30:33Z", + "modified": "2024-01-30T21:30:29Z", "published": "2024-01-24T21:30:33Z", "aliases": [ "CVE-2024-22751" ], "details": "D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-24T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-6grj-h983-99rg/GHSA-6grj-h983-99rg.json b/advisories/unreviewed/2024/01/GHSA-6grj-h983-99rg/GHSA-6grj-h983-99rg.json index f9cd34ca23a..d35dd4b53ee 100644 --- a/advisories/unreviewed/2024/01/GHSA-6grj-h983-99rg/GHSA-6grj-h983-99rg.json +++ b/advisories/unreviewed/2024/01/GHSA-6grj-h983-99rg/GHSA-6grj-h983-99rg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6grj-h983-99rg", - "modified": "2024-01-23T21:30:21Z", + "modified": "2024-01-30T21:30:28Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-47199" ], "details": "An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThis vulnerability is similar to, but not identical to, CVE-2023-47193.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-6pp8-37pj-mhcc/GHSA-6pp8-37pj-mhcc.json b/advisories/unreviewed/2024/01/GHSA-6pp8-37pj-mhcc/GHSA-6pp8-37pj-mhcc.json index a1e675d4cac..c13cd12ea40 100644 --- a/advisories/unreviewed/2024/01/GHSA-6pp8-37pj-mhcc/GHSA-6pp8-37pj-mhcc.json +++ b/advisories/unreviewed/2024/01/GHSA-6pp8-37pj-mhcc/GHSA-6pp8-37pj-mhcc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6pp8-37pj-mhcc", - "modified": "2024-01-23T21:30:21Z", + "modified": "2024-01-30T21:30:28Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-52325" ], "details": "A local file inclusion vulnerability in one of Trend Micro Apex Central's widgets could allow a remote attacker to execute arbitrary code on affected installations.\n\nPlease note: this vulnerability must be used in conjunction with another one to exploit an affected system. In addition, an attacker must first obtain a valid set of credentials on target system in order to exploit this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-78p2-p949-pjvr/GHSA-78p2-p949-pjvr.json b/advisories/unreviewed/2024/01/GHSA-78p2-p949-pjvr/GHSA-78p2-p949-pjvr.json index dc228a6ceb7..ee0259d3837 100644 --- a/advisories/unreviewed/2024/01/GHSA-78p2-p949-pjvr/GHSA-78p2-p949-pjvr.json +++ b/advisories/unreviewed/2024/01/GHSA-78p2-p949-pjvr/GHSA-78p2-p949-pjvr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-78p2-p949-pjvr", - "modified": "2024-01-24T18:31:01Z", + "modified": "2024-01-30T21:30:28Z", "published": "2024-01-24T18:31:01Z", "aliases": [ "CVE-2023-52038" ], "details": "An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-24T18:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-7j77-3p87-xr63/GHSA-7j77-3p87-xr63.json b/advisories/unreviewed/2024/01/GHSA-7j77-3p87-xr63/GHSA-7j77-3p87-xr63.json index ed818b64aff..94cdebc404e 100644 --- a/advisories/unreviewed/2024/01/GHSA-7j77-3p87-xr63/GHSA-7j77-3p87-xr63.json +++ b/advisories/unreviewed/2024/01/GHSA-7j77-3p87-xr63/GHSA-7j77-3p87-xr63.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7j77-3p87-xr63", - "modified": "2024-01-24T18:31:01Z", + "modified": "2024-01-30T21:30:28Z", "published": "2024-01-24T18:31:01Z", "aliases": [ "CVE-2023-52039" ], "details": "An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-24T18:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-8r5c-mgwc-qg49/GHSA-8r5c-mgwc-qg49.json b/advisories/unreviewed/2024/01/GHSA-8r5c-mgwc-qg49/GHSA-8r5c-mgwc-qg49.json index 2288b5f2417..55c6a4d9955 100644 --- a/advisories/unreviewed/2024/01/GHSA-8r5c-mgwc-qg49/GHSA-8r5c-mgwc-qg49.json +++ b/advisories/unreviewed/2024/01/GHSA-8r5c-mgwc-qg49/GHSA-8r5c-mgwc-qg49.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8r5c-mgwc-qg49", - "modified": "2024-01-24T09:30:25Z", + "modified": "2024-01-30T21:30:28Z", "published": "2024-01-24T09:30:25Z", "aliases": [ "CVE-2023-51711" ], "details": "An issue was discovered in Regify Regipay Client for Windows version 4.5.1.0 allows DLL hijacking: a user can trigger the execution of arbitrary code every time the product is executed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-427" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-24T07:15:47Z" diff --git a/advisories/unreviewed/2024/01/GHSA-c5vx-x65g-94m5/GHSA-c5vx-x65g-94m5.json b/advisories/unreviewed/2024/01/GHSA-c5vx-x65g-94m5/GHSA-c5vx-x65g-94m5.json index a740e434a4d..7a11cd892d5 100644 --- a/advisories/unreviewed/2024/01/GHSA-c5vx-x65g-94m5/GHSA-c5vx-x65g-94m5.json +++ b/advisories/unreviewed/2024/01/GHSA-c5vx-x65g-94m5/GHSA-c5vx-x65g-94m5.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-h7wp-7q3v-7m5w/GHSA-h7wp-7q3v-7m5w.json b/advisories/unreviewed/2024/01/GHSA-h7wp-7q3v-7m5w/GHSA-h7wp-7q3v-7m5w.json new file mode 100644 index 00000000000..e5481f1110b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-h7wp-7q3v-7m5w/GHSA-h7wp-7q3v-7m5w.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7wp-7q3v-7m5w", + "modified": "2024-01-30T21:30:29Z", + "published": "2024-01-30T21:30:29Z", + "aliases": [ + "CVE-2023-5389" + ], + "details": "\nAn attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion VirtualUOC and UOC . This exploit could be used to write a file that may result in unexpected behavior based on configuration changes or updating of files that could result in subsequent execution of a malicious application if triggered. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5389" + }, + { + "type": "WEB", + "url": "https://process.honeywell.com" + }, + { + "type": "WEB", + "url": "https://www.honeywell.com/us/en/product-security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-749" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T20:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-j2p7-j8v8-q5g2/GHSA-j2p7-j8v8-q5g2.json b/advisories/unreviewed/2024/01/GHSA-j2p7-j8v8-q5g2/GHSA-j2p7-j8v8-q5g2.json index 2630d364f1d..35a82159218 100644 --- a/advisories/unreviewed/2024/01/GHSA-j2p7-j8v8-q5g2/GHSA-j2p7-j8v8-q5g2.json +++ b/advisories/unreviewed/2024/01/GHSA-j2p7-j8v8-q5g2/GHSA-j2p7-j8v8-q5g2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j2p7-j8v8-q5g2", - "modified": "2024-01-24T18:31:01Z", + "modified": "2024-01-30T21:30:28Z", "published": "2024-01-24T18:31:01Z", "aliases": [ "CVE-2024-22725" ], "details": "Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's error reporting.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-24T16:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-jjfr-pq2x-mf69/GHSA-jjfr-pq2x-mf69.json b/advisories/unreviewed/2024/01/GHSA-jjfr-pq2x-mf69/GHSA-jjfr-pq2x-mf69.json index 5cbed3aa5ad..63a8d0a6b8b 100644 --- a/advisories/unreviewed/2024/01/GHSA-jjfr-pq2x-mf69/GHSA-jjfr-pq2x-mf69.json +++ b/advisories/unreviewed/2024/01/GHSA-jjfr-pq2x-mf69/GHSA-jjfr-pq2x-mf69.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jjfr-pq2x-mf69", - "modified": "2024-01-23T21:30:21Z", + "modified": "2024-01-30T21:30:28Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-52331" ], "details": "A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central could allow an attacker to interact with internal or local services directly.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-qfm4-9qqj-3w82/GHSA-qfm4-9qqj-3w82.json b/advisories/unreviewed/2024/01/GHSA-qfm4-9qqj-3w82/GHSA-qfm4-9qqj-3w82.json index 665fb3f569d..8eac0d04bea 100644 --- a/advisories/unreviewed/2024/01/GHSA-qfm4-9qqj-3w82/GHSA-qfm4-9qqj-3w82.json +++ b/advisories/unreviewed/2024/01/GHSA-qfm4-9qqj-3w82/GHSA-qfm4-9qqj-3w82.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qfm4-9qqj-3w82", - "modified": "2024-01-24T18:31:01Z", + "modified": "2024-01-30T21:30:28Z", "published": "2024-01-24T18:31:01Z", "aliases": [ "CVE-2024-22651" ], "details": "There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-24T16:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-v576-wfmr-x3x7/GHSA-v576-wfmr-x3x7.json b/advisories/unreviewed/2024/01/GHSA-v576-wfmr-x3x7/GHSA-v576-wfmr-x3x7.json index b620669b755..0c40dbaf29f 100644 --- a/advisories/unreviewed/2024/01/GHSA-v576-wfmr-x3x7/GHSA-v576-wfmr-x3x7.json +++ b/advisories/unreviewed/2024/01/GHSA-v576-wfmr-x3x7/GHSA-v576-wfmr-x3x7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v576-wfmr-x3x7", - "modified": "2024-01-23T21:30:21Z", + "modified": "2024-01-30T21:30:28Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-52324" ], "details": "An unrestricted file upload vulnerability in Trend Micro Apex Central could allow a remote attacker to create arbitrary files on affected installations.\n\nPlease note: although authentication is required to exploit this vulnerability, this vulnerability could be exploited when the attacker has any valid set of credentials. Also, this vulnerability could be potentially used in combination with another vulnerability to execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-vh9j-8vw4-5hp6/GHSA-vh9j-8vw4-5hp6.json b/advisories/unreviewed/2024/01/GHSA-vh9j-8vw4-5hp6/GHSA-vh9j-8vw4-5hp6.json index 2a2fca2b247..80540c5b979 100644 --- a/advisories/unreviewed/2024/01/GHSA-vh9j-8vw4-5hp6/GHSA-vh9j-8vw4-5hp6.json +++ b/advisories/unreviewed/2024/01/GHSA-vh9j-8vw4-5hp6/GHSA-vh9j-8vw4-5hp6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vh9j-8vw4-5hp6", - "modified": "2024-01-24T18:31:01Z", + "modified": "2024-01-30T21:30:28Z", "published": "2024-01-24T18:31:01Z", "aliases": [ "CVE-2023-52040" ], "details": "An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-24T18:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-xc7v-9m4q-8q68/GHSA-xc7v-9m4q-8q68.json b/advisories/unreviewed/2024/01/GHSA-xc7v-9m4q-8q68/GHSA-xc7v-9m4q-8q68.json index a805aac9c30..c4c75f64154 100644 --- a/advisories/unreviewed/2024/01/GHSA-xc7v-9m4q-8q68/GHSA-xc7v-9m4q-8q68.json +++ b/advisories/unreviewed/2024/01/GHSA-xc7v-9m4q-8q68/GHSA-xc7v-9m4q-8q68.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xc7v-9m4q-8q68", - "modified": "2024-01-24T18:31:01Z", + "modified": "2024-01-30T21:30:29Z", "published": "2024-01-24T18:31:01Z", "aliases": [ "CVE-2024-22720" ], "details": "Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-24T18:15:08Z"