Publish Advisories

GHSA-m5jc-r4gf-c6p8
GHSA-9qr8-h5jr-2gmw
GHSA-v4mv-7g6h-5vh8
GHSA-2jw2-fcpf-pj3x
GHSA-4x46-8gg7-f9vx
GHSA-565x-m8jw-g2f2
GHSA-5qgg-v88w-rgh6
GHSA-gj84-56mj-c85j
GHSA-q38f-wwqq-rr3v
GHSA-q8rm-wvjp-6qf3
GHSA-qfc7-gwmc-9vvr
GHSA-r64q-rcp8-3m38
GHSA-wpjj-rrr4-p36v
GHSA-37f3-8h34-h4xf
GHSA-5r8j-qmcm-7g7q
This commit is contained in:
advisory-database[bot]
2023-11-08 15:31:48 +00:00
parent d9dcff69c5
commit fc040da732
15 changed files with 100 additions and 36 deletions
@@ -52,6 +52,10 @@
"type": "WEB",
"url": "https://github.com/arduino/arduino-create-agent/releases/tag/1.3.3"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/11/msg00005.html"
},
{
"type": "WEB",
"url": "https://www.nozominetworks.com/blog/security-flaws-affect-a-component-of-the-arduino-create-cloud-ide"
@@ -65,6 +69,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2023-10-18T18:25:34Z",
"nvd_published_at": null
"nvd_published_at": "2023-10-18T21:15:09Z"
}
}
@@ -24,6 +24,14 @@
{
"type": "WEB",
"url": "https://security.paloaltonetworks.com/CVE-2023-0001"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/11/08/2"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/11/08/3"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v4mv-7g6h-5vh8",
"modified": "2023-08-02T15:30:51Z",
"modified": "2023-11-08T15:30:32Z",
"published": "2023-07-24T18:30:44Z",
"aliases": [
"CVE-2023-3812"
@@ -21,6 +21,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3812"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:6799"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:6813"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-3812"
@@ -36,11 +44,12 @@
],
"database_specific": {
"cwe_ids": [
"CWE-416",
"CWE-787"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-07-24T16:15:13Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2jw2-fcpf-pj3x",
"modified": "2023-10-29T09:30:27Z",
"modified": "2023-11-08T15:30:32Z",
"published": "2023-10-29T09:30:27Z",
"aliases": [
"CVE-2021-33637"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-665"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-29T08:15:20Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4x46-8gg7-f9vx",
"modified": "2023-10-26T06:30:25Z",
"modified": "2023-11-08T15:30:32Z",
"published": "2023-10-26T06:30:25Z",
"aliases": [
"CVE-2023-31421"
@@ -34,7 +34,7 @@
"cwe_ids": [
"CWE-295"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T04:15:16Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-565x-m8jw-g2f2",
"modified": "2023-10-27T06:31:01Z",
"modified": "2023-11-08T15:30:32Z",
"published": "2023-10-27T06:31:01Z",
"aliases": [
"CVE-2023-45498"
],
"details": "VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T04:15:10Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5qgg-v88w-rgh6",
"modified": "2023-10-28T21:30:24Z",
"modified": "2023-11-08T15:30:32Z",
"published": "2023-10-28T21:30:24Z",
"aliases": [
"CVE-2023-45897"
],
"details": "exfatprogs before 1.2.2 allows out-of-bounds memory access, such as in read_file_dentry_set.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
}
],
"affected": [
@@ -41,11 +44,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-28T21:15:07Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gj84-56mj-c85j",
"modified": "2023-10-27T06:31:02Z",
"modified": "2023-11-08T15:30:32Z",
"published": "2023-10-27T06:31:02Z",
"aliases": [
"CVE-2023-45499"
],
"details": "VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-798"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T04:15:10Z"
@@ -21,6 +21,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5367"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:6802"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:6808"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-5367"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q8rm-wvjp-6qf3",
"modified": "2023-10-29T09:30:27Z",
"modified": "2023-11-08T15:30:32Z",
"published": "2023-10-29T09:30:27Z",
"aliases": [
"CVE-2021-33636"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-665"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-29T08:15:20Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qfc7-gwmc-9vvr",
"modified": "2023-10-27T06:31:02Z",
"modified": "2023-11-08T15:30:32Z",
"published": "2023-10-27T06:31:02Z",
"aliases": [
"CVE-2023-46818"
],
"details": "An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T04:15:10Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r64q-rcp8-3m38",
"modified": "2023-10-29T09:30:27Z",
"modified": "2023-11-08T15:30:32Z",
"published": "2023-10-29T09:30:27Z",
"aliases": [
"CVE-2021-33635"
@@ -38,7 +38,7 @@
"cwe_ids": [
"CWE-665"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-29T08:15:20Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wpjj-rrr4-p36v",
"modified": "2023-10-30T06:30:31Z",
"modified": "2023-11-08T15:30:33Z",
"published": "2023-10-30T06:30:31Z",
"aliases": [
"CVE-2023-45746"
],
"details": "Cross-site scripting vulnerability in Movable Type series allows a remote authenticated attacker to inject an arbitrary script. Affected products/versions are as follows: Movable Type 7 r.5405 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.5405 and earlier (Movable Type 7 Series), Movable Type Premium 1.58 and earlier, Movable Type Premium Advanced 1.58 and earlier, Movable Type Cloud Edition (Version 7) r.5405 and earlier, and Movable Type Premium Cloud Edition 1.58 and earlier.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-30T05:15:09Z"
@@ -41,6 +41,22 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:6284"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:6795"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:6796"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:6798"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:6811"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-3972"
@@ -52,11 +68,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-379"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-11-01T16:15:08Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5r8j-qmcm-7g7q",
"modified": "2023-11-08T09:30:25Z",
"modified": "2023-11-08T15:30:33Z",
"published": "2023-11-08T09:30:25Z",
"aliases": [
"CVE-2023-39913"
@@ -21,6 +21,10 @@
{
"type": "WEB",
"url": "https://lists.apache.org/thread/lw30f4qlq3mhkhpljj16qw4fot3rg7v4"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/11/08/1"
}
],
"database_specific": {