diff --git a/advisories/unreviewed/2023/03/GHSA-7vmm-m8vp-g5h3/GHSA-7vmm-m8vp-g5h3.json b/advisories/unreviewed/2023/03/GHSA-7vmm-m8vp-g5h3/GHSA-7vmm-m8vp-g5h3.json index dc7b523d5cc..6dbca2d2c0a 100644 --- a/advisories/unreviewed/2023/03/GHSA-7vmm-m8vp-g5h3/GHSA-7vmm-m8vp-g5h3.json +++ b/advisories/unreviewed/2023/03/GHSA-7vmm-m8vp-g5h3/GHSA-7vmm-m8vp-g5h3.json @@ -40,6 +40,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/REDZB5J7WDN2P3NYWFO2NNJXSTOFUUKM/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YQ4ZGY5MDDHBEOQTD4IIA2RFID3ATPXA/" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/03/GHSA-9vj3-657p-m834/GHSA-9vj3-657p-m834.json b/advisories/unreviewed/2023/03/GHSA-9vj3-657p-m834/GHSA-9vj3-657p-m834.json new file mode 100644 index 00000000000..26d017b431e --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-9vj3-657p-m834/GHSA-9vj3-657p-m834.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vj3-657p-m834", + "modified": "2023-03-29T06:30:19Z", + "published": "2023-03-29T06:30:19Z", + "aliases": [ + "CVE-2023-1685" + ], + "details": "A vulnerability was found in HadSky up to 7.11.8. It has been declared as critical. This vulnerability affects unknown code of the file /install/index.php of the component Installation Interface. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-224242 is the identifier assigned to this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1685" + }, + { + "type": "WEB", + "url": "https://gitee.com/galaxies2580/cve/blob/master/hadSky.md" + }, + { + "type": "WEB", + "url": "https://gitee.com/xinbate/cve/blob/master/HadSky%20rce.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.224242" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.224242" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T06:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-vf28-x3q6-9qg2/GHSA-vf28-x3q6-9qg2.json b/advisories/unreviewed/2023/03/GHSA-vf28-x3q6-9qg2/GHSA-vf28-x3q6-9qg2.json new file mode 100644 index 00000000000..275e6d46b45 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-vf28-x3q6-9qg2/GHSA-vf28-x3q6-9qg2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vf28-x3q6-9qg2", + "modified": "2023-03-29T06:30:19Z", + "published": "2023-03-29T06:30:19Z", + "aliases": [ + "CVE-2023-23355" + ], + "details": "A vulnerability has been reported to affect multiple QNAP operating systems. If exploited, the vulnerability allows remote authenticated users to execute arbitrary commands via susceptible QNAP devices. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances), QVR. We have already fixed the vulnerability in the following operating system versions: QTS 5.0.1.2346 build 20230322 and later QuTS hero h5.0.1.2348 build 20230324 and later", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23355" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-10" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T05:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-wfp4-6h74-29hv/GHSA-wfp4-6h74-29hv.json b/advisories/unreviewed/2023/03/GHSA-wfp4-6h74-29hv/GHSA-wfp4-6h74-29hv.json new file mode 100644 index 00000000000..fc9fe9c272c --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-wfp4-6h74-29hv/GHSA-wfp4-6h74-29hv.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfp4-6h74-29hv", + "modified": "2023-03-29T06:30:19Z", + "published": "2023-03-29T06:30:19Z", + "aliases": [ + "CVE-2023-1684" + ], + "details": "A vulnerability was found in HadSky 7.7.16. It has been classified as problematic. This affects an unknown part of the file upload/index.php?c=app&a=superadmin:index. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224241 was assigned to this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1684" + }, + { + "type": "WEB", + "url": "https://gitee.com/wkstestete/cve/blob/master/upload/HadSky.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.224241" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.224241" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T04:15:00Z" + } +} \ No newline at end of file