Publish Advisories

GHSA-7vmm-m8vp-g5h3
GHSA-9vj3-657p-m834
GHSA-vf28-x3q6-9qg2
GHSA-wfp4-6h74-29hv
This commit is contained in:
advisory-database[bot]
2023-03-29 06:31:34 +00:00
parent 38c2cb0922
commit fc3ae35418
4 changed files with 129 additions and 0 deletions
@@ -40,6 +40,10 @@
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/REDZB5J7WDN2P3NYWFO2NNJXSTOFUUKM/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YQ4ZGY5MDDHBEOQTD4IIA2RFID3ATPXA/"
}
],
"database_specific": {
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9vj3-657p-m834",
"modified": "2023-03-29T06:30:19Z",
"published": "2023-03-29T06:30:19Z",
"aliases": [
"CVE-2023-1685"
],
"details": "A vulnerability was found in HadSky up to 7.11.8. It has been declared as critical. This vulnerability affects unknown code of the file /install/index.php of the component Installation Interface. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-224242 is the identifier assigned to this vulnerability.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1685"
},
{
"type": "WEB",
"url": "https://gitee.com/galaxies2580/cve/blob/master/hadSky.md"
},
{
"type": "WEB",
"url": "https://gitee.com/xinbate/cve/blob/master/HadSky%20rce.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.224242"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.224242"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-03-29T06:15:00Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vf28-x3q6-9qg2",
"modified": "2023-03-29T06:30:19Z",
"published": "2023-03-29T06:30:19Z",
"aliases": [
"CVE-2023-23355"
],
"details": "A vulnerability has been reported to affect multiple QNAP operating systems. If exploited, the vulnerability allows remote authenticated users to execute arbitrary commands via susceptible QNAP devices. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances), QVR. We have already fixed the vulnerability in the following operating system versions: QTS 5.0.1.2346 build 20230322 and later QuTS hero h5.0.1.2348 build 20230324 and later",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23355"
},
{
"type": "WEB",
"url": "https://www.qnap.com/en/security-advisory/qsa-23-10"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-03-29T05:15:00Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wfp4-6h74-29hv",
"modified": "2023-03-29T06:30:19Z",
"published": "2023-03-29T06:30:19Z",
"aliases": [
"CVE-2023-1684"
],
"details": "A vulnerability was found in HadSky 7.7.16. It has been classified as problematic. This affects an unknown part of the file upload/index.php?c=app&a=superadmin:index. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224241 was assigned to this vulnerability.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1684"
},
{
"type": "WEB",
"url": "https://gitee.com/wkstestete/cve/blob/master/upload/HadSky.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.224241"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.224241"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-03-29T04:15:00Z"
}
}