diff --git a/advisories/github-reviewed/2023/10/GHSA-m5jc-r4gf-c6p8/GHSA-m5jc-r4gf-c6p8.json b/advisories/github-reviewed/2023/10/GHSA-m5jc-r4gf-c6p8/GHSA-m5jc-r4gf-c6p8.json index 58aaaf68970..3cd9974a45f 100644 --- a/advisories/github-reviewed/2023/10/GHSA-m5jc-r4gf-c6p8/GHSA-m5jc-r4gf-c6p8.json +++ b/advisories/github-reviewed/2023/10/GHSA-m5jc-r4gf-c6p8/GHSA-m5jc-r4gf-c6p8.json @@ -52,6 +52,10 @@ "type": "WEB", "url": "https://github.com/arduino/arduino-create-agent/releases/tag/1.3.3" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/11/msg00005.html" + }, { "type": "WEB", "url": "https://www.nozominetworks.com/blog/security-flaws-affect-a-component-of-the-arduino-create-cloud-ide" @@ -65,6 +69,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-10-18T18:25:34Z", - "nvd_published_at": null + "nvd_published_at": "2023-10-18T21:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/02/GHSA-9qr8-h5jr-2gmw/GHSA-9qr8-h5jr-2gmw.json b/advisories/unreviewed/2023/02/GHSA-9qr8-h5jr-2gmw/GHSA-9qr8-h5jr-2gmw.json index 592d47d4e68..47f60d1a8fd 100644 --- a/advisories/unreviewed/2023/02/GHSA-9qr8-h5jr-2gmw/GHSA-9qr8-h5jr-2gmw.json +++ b/advisories/unreviewed/2023/02/GHSA-9qr8-h5jr-2gmw/GHSA-9qr8-h5jr-2gmw.json @@ -24,6 +24,14 @@ { "type": "WEB", "url": "https://security.paloaltonetworks.com/CVE-2023-0001" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/11/08/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/11/08/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/07/GHSA-v4mv-7g6h-5vh8/GHSA-v4mv-7g6h-5vh8.json b/advisories/unreviewed/2023/07/GHSA-v4mv-7g6h-5vh8/GHSA-v4mv-7g6h-5vh8.json index 0d4f96871be..3587ebf1a99 100644 --- a/advisories/unreviewed/2023/07/GHSA-v4mv-7g6h-5vh8/GHSA-v4mv-7g6h-5vh8.json +++ b/advisories/unreviewed/2023/07/GHSA-v4mv-7g6h-5vh8/GHSA-v4mv-7g6h-5vh8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v4mv-7g6h-5vh8", - "modified": "2023-08-02T15:30:51Z", + "modified": "2023-11-08T15:30:32Z", "published": "2023-07-24T18:30:44Z", "aliases": [ "CVE-2023-3812" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3812" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6799" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6813" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-3812" @@ -36,11 +44,12 @@ ], "database_specific": { "cwe_ids": [ + "CWE-416", "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-07-24T16:15:13Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-2jw2-fcpf-pj3x/GHSA-2jw2-fcpf-pj3x.json b/advisories/unreviewed/2023/10/GHSA-2jw2-fcpf-pj3x/GHSA-2jw2-fcpf-pj3x.json index 10775b9c0bf..8974b45a291 100644 --- a/advisories/unreviewed/2023/10/GHSA-2jw2-fcpf-pj3x/GHSA-2jw2-fcpf-pj3x.json +++ b/advisories/unreviewed/2023/10/GHSA-2jw2-fcpf-pj3x/GHSA-2jw2-fcpf-pj3x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2jw2-fcpf-pj3x", - "modified": "2023-10-29T09:30:27Z", + "modified": "2023-11-08T15:30:32Z", "published": "2023-10-29T09:30:27Z", "aliases": [ "CVE-2021-33637" @@ -38,7 +38,7 @@ "cwe_ids": [ "CWE-665" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-29T08:15:20Z" diff --git a/advisories/unreviewed/2023/10/GHSA-4x46-8gg7-f9vx/GHSA-4x46-8gg7-f9vx.json b/advisories/unreviewed/2023/10/GHSA-4x46-8gg7-f9vx/GHSA-4x46-8gg7-f9vx.json index 4ff45981613..d73972f8e3b 100644 --- a/advisories/unreviewed/2023/10/GHSA-4x46-8gg7-f9vx/GHSA-4x46-8gg7-f9vx.json +++ b/advisories/unreviewed/2023/10/GHSA-4x46-8gg7-f9vx/GHSA-4x46-8gg7-f9vx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4x46-8gg7-f9vx", - "modified": "2023-10-26T06:30:25Z", + "modified": "2023-11-08T15:30:32Z", "published": "2023-10-26T06:30:25Z", "aliases": [ "CVE-2023-31421" @@ -34,7 +34,7 @@ "cwe_ids": [ "CWE-295" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-26T04:15:16Z" diff --git a/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json b/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json index 279a74578e7..5be04425b35 100644 --- a/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json +++ b/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-565x-m8jw-g2f2", - "modified": "2023-10-27T06:31:01Z", + "modified": "2023-11-08T15:30:32Z", "published": "2023-10-27T06:31:01Z", "aliases": [ "CVE-2023-45498" ], "details": "VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-27T04:15:10Z" diff --git a/advisories/unreviewed/2023/10/GHSA-5qgg-v88w-rgh6/GHSA-5qgg-v88w-rgh6.json b/advisories/unreviewed/2023/10/GHSA-5qgg-v88w-rgh6/GHSA-5qgg-v88w-rgh6.json index b483977e691..75b44852bdb 100644 --- a/advisories/unreviewed/2023/10/GHSA-5qgg-v88w-rgh6/GHSA-5qgg-v88w-rgh6.json +++ b/advisories/unreviewed/2023/10/GHSA-5qgg-v88w-rgh6/GHSA-5qgg-v88w-rgh6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5qgg-v88w-rgh6", - "modified": "2023-10-28T21:30:24Z", + "modified": "2023-11-08T15:30:32Z", "published": "2023-10-28T21:30:24Z", "aliases": [ "CVE-2023-45897" ], "details": "exfatprogs before 1.2.2 allows out-of-bounds memory access, such as in read_file_dentry_set.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -41,11 +44,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-28T21:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json b/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json index 7b4bae21591..ca565c5cc74 100644 --- a/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json +++ b/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gj84-56mj-c85j", - "modified": "2023-10-27T06:31:02Z", + "modified": "2023-11-08T15:30:32Z", "published": "2023-10-27T06:31:02Z", "aliases": [ "CVE-2023-45499" ], "details": "VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-27T04:15:10Z" diff --git a/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json b/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json index 899dd114297..6734f8a9aaf 100644 --- a/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json +++ b/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5367" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6802" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6808" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-5367" diff --git a/advisories/unreviewed/2023/10/GHSA-q8rm-wvjp-6qf3/GHSA-q8rm-wvjp-6qf3.json b/advisories/unreviewed/2023/10/GHSA-q8rm-wvjp-6qf3/GHSA-q8rm-wvjp-6qf3.json index 715705901d9..c831cfb81c7 100644 --- a/advisories/unreviewed/2023/10/GHSA-q8rm-wvjp-6qf3/GHSA-q8rm-wvjp-6qf3.json +++ b/advisories/unreviewed/2023/10/GHSA-q8rm-wvjp-6qf3/GHSA-q8rm-wvjp-6qf3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q8rm-wvjp-6qf3", - "modified": "2023-10-29T09:30:27Z", + "modified": "2023-11-08T15:30:32Z", "published": "2023-10-29T09:30:27Z", "aliases": [ "CVE-2021-33636" @@ -38,7 +38,7 @@ "cwe_ids": [ "CWE-665" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-29T08:15:20Z" diff --git a/advisories/unreviewed/2023/10/GHSA-qfc7-gwmc-9vvr/GHSA-qfc7-gwmc-9vvr.json b/advisories/unreviewed/2023/10/GHSA-qfc7-gwmc-9vvr/GHSA-qfc7-gwmc-9vvr.json index f83cec04cd4..26820f62aec 100644 --- a/advisories/unreviewed/2023/10/GHSA-qfc7-gwmc-9vvr/GHSA-qfc7-gwmc-9vvr.json +++ b/advisories/unreviewed/2023/10/GHSA-qfc7-gwmc-9vvr/GHSA-qfc7-gwmc-9vvr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qfc7-gwmc-9vvr", - "modified": "2023-10-27T06:31:02Z", + "modified": "2023-11-08T15:30:32Z", "published": "2023-10-27T06:31:02Z", "aliases": [ "CVE-2023-46818" ], "details": "An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-27T04:15:10Z" diff --git a/advisories/unreviewed/2023/10/GHSA-r64q-rcp8-3m38/GHSA-r64q-rcp8-3m38.json b/advisories/unreviewed/2023/10/GHSA-r64q-rcp8-3m38/GHSA-r64q-rcp8-3m38.json index 499587c8af6..45208aba3e3 100644 --- a/advisories/unreviewed/2023/10/GHSA-r64q-rcp8-3m38/GHSA-r64q-rcp8-3m38.json +++ b/advisories/unreviewed/2023/10/GHSA-r64q-rcp8-3m38/GHSA-r64q-rcp8-3m38.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r64q-rcp8-3m38", - "modified": "2023-10-29T09:30:27Z", + "modified": "2023-11-08T15:30:32Z", "published": "2023-10-29T09:30:27Z", "aliases": [ "CVE-2021-33635" @@ -38,7 +38,7 @@ "cwe_ids": [ "CWE-665" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-29T08:15:20Z" diff --git a/advisories/unreviewed/2023/10/GHSA-wpjj-rrr4-p36v/GHSA-wpjj-rrr4-p36v.json b/advisories/unreviewed/2023/10/GHSA-wpjj-rrr4-p36v/GHSA-wpjj-rrr4-p36v.json index 8bac7d73d22..ad96b504ef8 100644 --- a/advisories/unreviewed/2023/10/GHSA-wpjj-rrr4-p36v/GHSA-wpjj-rrr4-p36v.json +++ b/advisories/unreviewed/2023/10/GHSA-wpjj-rrr4-p36v/GHSA-wpjj-rrr4-p36v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wpjj-rrr4-p36v", - "modified": "2023-10-30T06:30:31Z", + "modified": "2023-11-08T15:30:33Z", "published": "2023-10-30T06:30:31Z", "aliases": [ "CVE-2023-45746" ], "details": "Cross-site scripting vulnerability in Movable Type series allows a remote authenticated attacker to inject an arbitrary script. Affected products/versions are as follows: Movable Type 7 r.5405 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.5405 and earlier (Movable Type 7 Series), Movable Type Premium 1.58 and earlier, Movable Type Premium Advanced 1.58 and earlier, Movable Type Cloud Edition (Version 7) r.5405 and earlier, and Movable Type Premium Cloud Edition 1.58 and earlier.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-30T05:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-37f3-8h34-h4xf/GHSA-37f3-8h34-h4xf.json b/advisories/unreviewed/2023/11/GHSA-37f3-8h34-h4xf/GHSA-37f3-8h34-h4xf.json index af41697aa2a..8284cd4e37b 100644 --- a/advisories/unreviewed/2023/11/GHSA-37f3-8h34-h4xf/GHSA-37f3-8h34-h4xf.json +++ b/advisories/unreviewed/2023/11/GHSA-37f3-8h34-h4xf/GHSA-37f3-8h34-h4xf.json @@ -41,6 +41,22 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2023:6284" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6795" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6796" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6798" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6811" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-3972" @@ -52,11 +68,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-379" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T16:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5r8j-qmcm-7g7q/GHSA-5r8j-qmcm-7g7q.json b/advisories/unreviewed/2023/11/GHSA-5r8j-qmcm-7g7q/GHSA-5r8j-qmcm-7g7q.json index 20a7a008302..7d9db576d17 100644 --- a/advisories/unreviewed/2023/11/GHSA-5r8j-qmcm-7g7q/GHSA-5r8j-qmcm-7g7q.json +++ b/advisories/unreviewed/2023/11/GHSA-5r8j-qmcm-7g7q/GHSA-5r8j-qmcm-7g7q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5r8j-qmcm-7g7q", - "modified": "2023-11-08T09:30:25Z", + "modified": "2023-11-08T15:30:33Z", "published": "2023-11-08T09:30:25Z", "aliases": [ "CVE-2023-39913" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/lw30f4qlq3mhkhpljj16qw4fot3rg7v4" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/11/08/1" } ], "database_specific": {