mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-449w-g66x-h54j GHSA-4895-cxh8-gwhw GHSA-5m86-gj68-x34m GHSA-6jf4-pg2m-9838 GHSA-6xr5-p6cj-8mrm GHSA-77jm-r76q-g5ph GHSA-fcww-v4hr-rgfr GHSA-g9rx-x2rh-fgcf GHSA-p4ff-mmmp-q474 GHSA-p53v-hm2g-p66x GHSA-vvp5-2ffm-gmvh GHSA-x697-v25m-6phv GHSA-xr5r-3m93-q3f2
This commit is contained in:
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-449w-g66x-h54j",
|
||||
"modified": "2024-01-16T12:30:25Z",
|
||||
"published": "2024-01-16T12:30:25Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52100"
|
||||
],
|
||||
"details": "The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affect availability.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52100"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T10:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4895-cxh8-gwhw",
|
||||
"modified": "2024-01-16T12:30:25Z",
|
||||
"published": "2024-01-16T12:30:25Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52099"
|
||||
],
|
||||
"details": "Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect service confidentiality.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52099"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T10:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5m86-gj68-x34m",
|
||||
"modified": "2024-01-16T12:30:26Z",
|
||||
"published": "2024-01-16T12:30:26Z",
|
||||
"aliases": [
|
||||
"CVE-2024-0556"
|
||||
],
|
||||
"details": "A Weak Cryptography for Passwords vulnerability has been detected on WIC200 affecting version 1.1. This vulnerability allows a remote user to intercept the traffic and retrieve the credentials from another user and decode it in base64 allowing the attacker to see the credentials in plain text.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0556"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-full-compass-systems-wic1200"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-261"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T11:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6jf4-pg2m-9838",
|
||||
"modified": "2024-01-16T12:30:25Z",
|
||||
"published": "2024-01-16T12:30:25Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52101"
|
||||
],
|
||||
"details": "Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52101"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T10:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6xr5-p6cj-8mrm",
|
||||
"modified": "2024-01-16T12:30:26Z",
|
||||
"published": "2024-01-16T12:30:26Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52104"
|
||||
],
|
||||
"details": "Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52104"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T10:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-77jm-r76q-g5ph",
|
||||
"modified": "2024-01-16T12:30:26Z",
|
||||
"published": "2024-01-16T12:30:26Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52106"
|
||||
],
|
||||
"details": "The DownloadProviderMain module has a vulnerability in API permission verification. Successful exploitation of this vulnerability may affect integrity and availability.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52106"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T10:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fcww-v4hr-rgfr",
|
||||
"modified": "2024-01-16T12:30:25Z",
|
||||
"published": "2024-01-16T12:30:25Z",
|
||||
"aliases": [
|
||||
"CVE-2023-34063"
|
||||
],
|
||||
"details": "Aria Automation contains a Missing Access Control vulnerability.\n\n\nAn authenticated malicious actor may \nexploit this vulnerability leading to unauthorized access to remote \norganizations and workflows.\n\n",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34063"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.vmware.com/security/advisories/VMSA-2024-0001.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T10:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-g9rx-x2rh-fgcf",
|
||||
"modified": "2024-01-16T12:30:26Z",
|
||||
"published": "2024-01-16T12:30:26Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52103"
|
||||
],
|
||||
"details": "Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52103"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-120"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T10:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-p4ff-mmmp-q474",
|
||||
"modified": "2024-01-16T12:30:26Z",
|
||||
"published": "2024-01-16T12:30:26Z",
|
||||
"aliases": [
|
||||
"CVE-2024-0554"
|
||||
],
|
||||
"details": "A Cross-site scripting (XSS) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could store a malicious javascript payload in the device model parameter via '/setup/diags_ir_learn.asp', allowing the attacker to retrieve the session details of another user.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0554"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-full-compass-systems-wic1200"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T11:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-p53v-hm2g-p66x",
|
||||
"modified": "2024-01-16T12:30:25Z",
|
||||
"published": "2024-01-16T12:30:25Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52102"
|
||||
],
|
||||
"details": "Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52102"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T10:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-vvp5-2ffm-gmvh",
|
||||
"modified": "2024-01-16T12:30:26Z",
|
||||
"published": "2024-01-16T12:30:26Z",
|
||||
"aliases": [
|
||||
"CVE-2024-0555"
|
||||
],
|
||||
"details": "A Cross-Site Request Forgery (CSRF) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could lead another user into executing unwanted actions inside the application they are logged in. This vulnerability is possible due to the lack of propper CSRF token implementation.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0555"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-full-compass-systems-wic1200"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-352"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T11:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,50 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-x697-v25m-6phv",
|
||||
"modified": "2024-01-16T12:30:26Z",
|
||||
"published": "2024-01-16T12:30:26Z",
|
||||
"aliases": [
|
||||
"CVE-2024-0553"
|
||||
],
|
||||
"details": "A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0553"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/security/cve/CVE-2024-0553"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258412"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://gitlab.com/gnutls/gnutls/-/issues/1522"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.gnupg.org/pipermail/gnutls-help/2024-January/004841.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-203"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T12:15:45Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-xr5r-3m93-q3f2",
|
||||
"modified": "2024-01-16T12:30:26Z",
|
||||
"published": "2024-01-16T12:30:26Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52105"
|
||||
],
|
||||
"details": "The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52105"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T10:15:07Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user