diff --git a/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json b/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json index 9bfaddd63ad..bfe3cd14e5e 100644 --- a/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json +++ b/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json @@ -57,6 +57,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2023:7533" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0010" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-5367" diff --git a/advisories/unreviewed/2023/12/GHSA-2xj9-j5v2-96c8/GHSA-2xj9-j5v2-96c8.json b/advisories/unreviewed/2023/12/GHSA-2xj9-j5v2-96c8/GHSA-2xj9-j5v2-96c8.json index e301393ab5c..e4f6885b505 100644 --- a/advisories/unreviewed/2023/12/GHSA-2xj9-j5v2-96c8/GHSA-2xj9-j5v2-96c8.json +++ b/advisories/unreviewed/2023/12/GHSA-2xj9-j5v2-96c8/GHSA-2xj9-j5v2-96c8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2xj9-j5v2-96c8", - "modified": "2023-12-21T21:30:31Z", + "modified": "2024-01-02T15:30:24Z", "published": "2023-12-21T21:30:31Z", "aliases": [ "CVE-2023-48686" diff --git a/advisories/unreviewed/2023/12/GHSA-4827-2m3r-j4qh/GHSA-4827-2m3r-j4qh.json b/advisories/unreviewed/2023/12/GHSA-4827-2m3r-j4qh/GHSA-4827-2m3r-j4qh.json index 897a95fb53d..87f8d8a014a 100644 --- a/advisories/unreviewed/2023/12/GHSA-4827-2m3r-j4qh/GHSA-4827-2m3r-j4qh.json +++ b/advisories/unreviewed/2023/12/GHSA-4827-2m3r-j4qh/GHSA-4827-2m3r-j4qh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4827-2m3r-j4qh", - "modified": "2023-12-28T00:30:20Z", + "modified": "2024-01-02T15:30:24Z", "published": "2023-12-21T18:30:23Z", "aliases": [ "CVE-2023-45119" diff --git a/advisories/unreviewed/2023/12/GHSA-9pmm-p2wc-hfx4/GHSA-9pmm-p2wc-hfx4.json b/advisories/unreviewed/2023/12/GHSA-9pmm-p2wc-hfx4/GHSA-9pmm-p2wc-hfx4.json index 315d3f0158d..0dfde904297 100644 --- a/advisories/unreviewed/2023/12/GHSA-9pmm-p2wc-hfx4/GHSA-9pmm-p2wc-hfx4.json +++ b/advisories/unreviewed/2023/12/GHSA-9pmm-p2wc-hfx4/GHSA-9pmm-p2wc-hfx4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9pmm-p2wc-hfx4", - "modified": "2023-12-29T03:30:28Z", + "modified": "2024-01-02T15:30:24Z", "published": "2023-12-21T18:30:23Z", "aliases": [ "CVE-2023-45120" diff --git a/advisories/unreviewed/2023/12/GHSA-cj6f-97f2-wp7j/GHSA-cj6f-97f2-wp7j.json b/advisories/unreviewed/2023/12/GHSA-cj6f-97f2-wp7j/GHSA-cj6f-97f2-wp7j.json index fde7a6908b7..a561ba65557 100644 --- a/advisories/unreviewed/2023/12/GHSA-cj6f-97f2-wp7j/GHSA-cj6f-97f2-wp7j.json +++ b/advisories/unreviewed/2023/12/GHSA-cj6f-97f2-wp7j/GHSA-cj6f-97f2-wp7j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cj6f-97f2-wp7j", - "modified": "2023-12-20T00:32:44Z", + "modified": "2024-01-02T15:30:23Z", "published": "2023-12-20T00:32:44Z", "aliases": [ "CVE-2023-49147" ], "details": "An issue was discovered in PDF24 Creator 11.14.0. The configuration of the msi installer file was found to produce a visible cmd.exe window when using the repair function of msiexec.exe. This allows an unprivileged local attacker to use a chain of actions (e.g., an oplock on faxPrnInst.log) to open a SYSTEM cmd.exe.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-19T23:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-f2p7-3jq8-v8ph/GHSA-f2p7-3jq8-v8ph.json b/advisories/unreviewed/2023/12/GHSA-f2p7-3jq8-v8ph/GHSA-f2p7-3jq8-v8ph.json index e0d1f9a657a..40f84ba443c 100644 --- a/advisories/unreviewed/2023/12/GHSA-f2p7-3jq8-v8ph/GHSA-f2p7-3jq8-v8ph.json +++ b/advisories/unreviewed/2023/12/GHSA-f2p7-3jq8-v8ph/GHSA-f2p7-3jq8-v8ph.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f2p7-3jq8-v8ph", - "modified": "2023-12-21T21:30:31Z", + "modified": "2024-01-02T15:30:25Z", "published": "2023-12-21T21:30:31Z", "aliases": [ "CVE-2023-48690" diff --git a/advisories/unreviewed/2023/12/GHSA-f5wq-j5xc-xjc7/GHSA-f5wq-j5xc-xjc7.json b/advisories/unreviewed/2023/12/GHSA-f5wq-j5xc-xjc7/GHSA-f5wq-j5xc-xjc7.json index e6756bf82f6..de26cab82dc 100644 --- a/advisories/unreviewed/2023/12/GHSA-f5wq-j5xc-xjc7/GHSA-f5wq-j5xc-xjc7.json +++ b/advisories/unreviewed/2023/12/GHSA-f5wq-j5xc-xjc7/GHSA-f5wq-j5xc-xjc7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f5wq-j5xc-xjc7", - "modified": "2023-12-29T15:30:30Z", + "modified": "2024-01-02T15:30:24Z", "published": "2023-12-21T18:30:23Z", "aliases": [ "CVE-2023-45123" diff --git a/advisories/unreviewed/2023/12/GHSA-fwrj-5c8f-f8h2/GHSA-fwrj-5c8f-f8h2.json b/advisories/unreviewed/2023/12/GHSA-fwrj-5c8f-f8h2/GHSA-fwrj-5c8f-f8h2.json index 093cbcc47bf..d72cf092e00 100644 --- a/advisories/unreviewed/2023/12/GHSA-fwrj-5c8f-f8h2/GHSA-fwrj-5c8f-f8h2.json +++ b/advisories/unreviewed/2023/12/GHSA-fwrj-5c8f-f8h2/GHSA-fwrj-5c8f-f8h2.json @@ -25,6 +25,42 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2023:7886" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0006" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0009" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0010" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0014" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0015" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0016" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0017" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0018" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0020" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6478" diff --git a/advisories/unreviewed/2023/12/GHSA-hvrj-r9f4-xr39/GHSA-hvrj-r9f4-xr39.json b/advisories/unreviewed/2023/12/GHSA-hvrj-r9f4-xr39/GHSA-hvrj-r9f4-xr39.json index e6a167346c8..477a2b059d4 100644 --- a/advisories/unreviewed/2023/12/GHSA-hvrj-r9f4-xr39/GHSA-hvrj-r9f4-xr39.json +++ b/advisories/unreviewed/2023/12/GHSA-hvrj-r9f4-xr39/GHSA-hvrj-r9f4-xr39.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hvrj-r9f4-xr39", - "modified": "2023-12-20T03:30:23Z", + "modified": "2024-01-02T15:30:23Z", "published": "2023-12-20T03:30:23Z", "aliases": [ "CVE-2023-27172" ], "details": "Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-307" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-20T01:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-j4xm-8c7j-fjwj/GHSA-j4xm-8c7j-fjwj.json b/advisories/unreviewed/2023/12/GHSA-j4xm-8c7j-fjwj/GHSA-j4xm-8c7j-fjwj.json index 0b2ee9491ff..34b939b97fb 100644 --- a/advisories/unreviewed/2023/12/GHSA-j4xm-8c7j-fjwj/GHSA-j4xm-8c7j-fjwj.json +++ b/advisories/unreviewed/2023/12/GHSA-j4xm-8c7j-fjwj/GHSA-j4xm-8c7j-fjwj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j4xm-8c7j-fjwj", - "modified": "2023-12-28T00:30:19Z", + "modified": "2024-01-02T15:30:24Z", "published": "2023-12-21T18:30:22Z", "aliases": [ "CVE-2023-45115" diff --git a/advisories/unreviewed/2023/12/GHSA-jfjv-fcvm-w4c8/GHSA-jfjv-fcvm-w4c8.json b/advisories/unreviewed/2023/12/GHSA-jfjv-fcvm-w4c8/GHSA-jfjv-fcvm-w4c8.json index 52d239829f9..f94f025b8fa 100644 --- a/advisories/unreviewed/2023/12/GHSA-jfjv-fcvm-w4c8/GHSA-jfjv-fcvm-w4c8.json +++ b/advisories/unreviewed/2023/12/GHSA-jfjv-fcvm-w4c8/GHSA-jfjv-fcvm-w4c8.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-jh6c-99xj-2gpm/GHSA-jh6c-99xj-2gpm.json b/advisories/unreviewed/2023/12/GHSA-jh6c-99xj-2gpm/GHSA-jh6c-99xj-2gpm.json index 8e6859142a4..db545eee69a 100644 --- a/advisories/unreviewed/2023/12/GHSA-jh6c-99xj-2gpm/GHSA-jh6c-99xj-2gpm.json +++ b/advisories/unreviewed/2023/12/GHSA-jh6c-99xj-2gpm/GHSA-jh6c-99xj-2gpm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jh6c-99xj-2gpm", - "modified": "2023-12-29T15:30:30Z", + "modified": "2024-01-02T15:30:24Z", "published": "2023-12-21T18:30:23Z", "aliases": [ "CVE-2023-45122" diff --git a/advisories/unreviewed/2023/12/GHSA-jxpp-2jgf-79rr/GHSA-jxpp-2jgf-79rr.json b/advisories/unreviewed/2023/12/GHSA-jxpp-2jgf-79rr/GHSA-jxpp-2jgf-79rr.json index 647b67d61e5..5166f805a30 100644 --- a/advisories/unreviewed/2023/12/GHSA-jxpp-2jgf-79rr/GHSA-jxpp-2jgf-79rr.json +++ b/advisories/unreviewed/2023/12/GHSA-jxpp-2jgf-79rr/GHSA-jxpp-2jgf-79rr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jxpp-2jgf-79rr", - "modified": "2023-12-28T00:30:20Z", + "modified": "2024-01-02T15:30:24Z", "published": "2023-12-21T18:30:22Z", "aliases": [ "CVE-2023-45118" diff --git a/advisories/unreviewed/2023/12/GHSA-mh5h-4v4h-vcvq/GHSA-mh5h-4v4h-vcvq.json b/advisories/unreviewed/2023/12/GHSA-mh5h-4v4h-vcvq/GHSA-mh5h-4v4h-vcvq.json index 9af353c84fb..d6cb57016ad 100644 --- a/advisories/unreviewed/2023/12/GHSA-mh5h-4v4h-vcvq/GHSA-mh5h-4v4h-vcvq.json +++ b/advisories/unreviewed/2023/12/GHSA-mh5h-4v4h-vcvq/GHSA-mh5h-4v4h-vcvq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mh5h-4v4h-vcvq", - "modified": "2023-12-28T21:30:38Z", + "modified": "2024-01-02T15:30:24Z", "published": "2023-12-21T21:30:30Z", "aliases": [ "CVE-2023-45124" diff --git a/advisories/unreviewed/2023/12/GHSA-pcm9-gv4v-rfw2/GHSA-pcm9-gv4v-rfw2.json b/advisories/unreviewed/2023/12/GHSA-pcm9-gv4v-rfw2/GHSA-pcm9-gv4v-rfw2.json index 3fa34b582a5..6a795cd6ca5 100644 --- a/advisories/unreviewed/2023/12/GHSA-pcm9-gv4v-rfw2/GHSA-pcm9-gv4v-rfw2.json +++ b/advisories/unreviewed/2023/12/GHSA-pcm9-gv4v-rfw2/GHSA-pcm9-gv4v-rfw2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pcm9-gv4v-rfw2", - "modified": "2023-12-28T21:30:38Z", + "modified": "2024-01-02T15:30:24Z", "published": "2023-12-21T21:30:30Z", "aliases": [ "CVE-2023-45125" diff --git a/advisories/unreviewed/2023/12/GHSA-pxgf-7mqc-v7vx/GHSA-pxgf-7mqc-v7vx.json b/advisories/unreviewed/2023/12/GHSA-pxgf-7mqc-v7vx/GHSA-pxgf-7mqc-v7vx.json index f7ac2ac7f76..c24183c6cf3 100644 --- a/advisories/unreviewed/2023/12/GHSA-pxgf-7mqc-v7vx/GHSA-pxgf-7mqc-v7vx.json +++ b/advisories/unreviewed/2023/12/GHSA-pxgf-7mqc-v7vx/GHSA-pxgf-7mqc-v7vx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pxgf-7mqc-v7vx", - "modified": "2023-12-28T21:30:38Z", + "modified": "2024-01-02T15:30:24Z", "published": "2023-12-21T21:30:30Z", "aliases": [ "CVE-2023-45127" diff --git a/advisories/unreviewed/2023/12/GHSA-q8qj-jcw4-vf7x/GHSA-q8qj-jcw4-vf7x.json b/advisories/unreviewed/2023/12/GHSA-q8qj-jcw4-vf7x/GHSA-q8qj-jcw4-vf7x.json index 2a33248230e..c0f0b15c64c 100644 --- a/advisories/unreviewed/2023/12/GHSA-q8qj-jcw4-vf7x/GHSA-q8qj-jcw4-vf7x.json +++ b/advisories/unreviewed/2023/12/GHSA-q8qj-jcw4-vf7x/GHSA-q8qj-jcw4-vf7x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q8qj-jcw4-vf7x", - "modified": "2023-12-20T00:32:45Z", + "modified": "2024-01-02T15:30:23Z", "published": "2023-12-20T00:32:45Z", "aliases": [ "CVE-2023-45887" ], "details": "DS Wireless Communication (DWC) with DWC_VERSION_3 and DWC_VERSION_11 allows remote attackers to execute arbitrary code on a game-playing client's machine via a modified GPCM message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-20T00:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-qfq7-6m5h-vcmw/GHSA-qfq7-6m5h-vcmw.json b/advisories/unreviewed/2023/12/GHSA-qfq7-6m5h-vcmw/GHSA-qfq7-6m5h-vcmw.json index 656ec4d0ab2..68f9e3308e4 100644 --- a/advisories/unreviewed/2023/12/GHSA-qfq7-6m5h-vcmw/GHSA-qfq7-6m5h-vcmw.json +++ b/advisories/unreviewed/2023/12/GHSA-qfq7-6m5h-vcmw/GHSA-qfq7-6m5h-vcmw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qfq7-6m5h-vcmw", - "modified": "2023-12-21T21:30:31Z", + "modified": "2024-01-02T15:30:25Z", "published": "2023-12-21T21:30:31Z", "aliases": [ "CVE-2023-48688" diff --git a/advisories/unreviewed/2023/12/GHSA-qjw8-8m2x-jvh6/GHSA-qjw8-8m2x-jvh6.json b/advisories/unreviewed/2023/12/GHSA-qjw8-8m2x-jvh6/GHSA-qjw8-8m2x-jvh6.json index d8121777a2e..0fc8b4c4cd1 100644 --- a/advisories/unreviewed/2023/12/GHSA-qjw8-8m2x-jvh6/GHSA-qjw8-8m2x-jvh6.json +++ b/advisories/unreviewed/2023/12/GHSA-qjw8-8m2x-jvh6/GHSA-qjw8-8m2x-jvh6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qjw8-8m2x-jvh6", - "modified": "2023-12-28T00:30:20Z", + "modified": "2024-01-02T15:30:24Z", "published": "2023-12-21T18:30:22Z", "aliases": [ "CVE-2023-45117" diff --git a/advisories/unreviewed/2023/12/GHSA-qp5q-m8rc-5r2q/GHSA-qp5q-m8rc-5r2q.json b/advisories/unreviewed/2023/12/GHSA-qp5q-m8rc-5r2q/GHSA-qp5q-m8rc-5r2q.json index de3056ebdd6..c42f72fcab2 100644 --- a/advisories/unreviewed/2023/12/GHSA-qp5q-m8rc-5r2q/GHSA-qp5q-m8rc-5r2q.json +++ b/advisories/unreviewed/2023/12/GHSA-qp5q-m8rc-5r2q/GHSA-qp5q-m8rc-5r2q.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-qp7j-9526-r655/GHSA-qp7j-9526-r655.json b/advisories/unreviewed/2023/12/GHSA-qp7j-9526-r655/GHSA-qp7j-9526-r655.json index 1bfb23c38d6..bfe7628bca9 100644 --- a/advisories/unreviewed/2023/12/GHSA-qp7j-9526-r655/GHSA-qp7j-9526-r655.json +++ b/advisories/unreviewed/2023/12/GHSA-qp7j-9526-r655/GHSA-qp7j-9526-r655.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qp7j-9526-r655", - "modified": "2023-12-28T21:30:38Z", + "modified": "2024-01-02T15:30:24Z", "published": "2023-12-21T21:30:30Z", "aliases": [ "CVE-2023-45126" diff --git a/advisories/unreviewed/2023/12/GHSA-vg76-xrj2-3p56/GHSA-vg76-xrj2-3p56.json b/advisories/unreviewed/2023/12/GHSA-vg76-xrj2-3p56/GHSA-vg76-xrj2-3p56.json index 5b48b717e09..8ef8435d5eb 100644 --- a/advisories/unreviewed/2023/12/GHSA-vg76-xrj2-3p56/GHSA-vg76-xrj2-3p56.json +++ b/advisories/unreviewed/2023/12/GHSA-vg76-xrj2-3p56/GHSA-vg76-xrj2-3p56.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vg76-xrj2-3p56", - "modified": "2023-12-29T03:30:28Z", + "modified": "2024-01-02T15:30:24Z", "published": "2023-12-21T18:30:23Z", "aliases": [ "CVE-2023-45121" diff --git a/advisories/unreviewed/2023/12/GHSA-x8w2-5hj8-c5rf/GHSA-x8w2-5hj8-c5rf.json b/advisories/unreviewed/2023/12/GHSA-x8w2-5hj8-c5rf/GHSA-x8w2-5hj8-c5rf.json index 99700329113..aa34c56bbd8 100644 --- a/advisories/unreviewed/2023/12/GHSA-x8w2-5hj8-c5rf/GHSA-x8w2-5hj8-c5rf.json +++ b/advisories/unreviewed/2023/12/GHSA-x8w2-5hj8-c5rf/GHSA-x8w2-5hj8-c5rf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x8w2-5hj8-c5rf", - "modified": "2023-12-19T00:30:20Z", + "modified": "2024-01-02T15:30:23Z", "published": "2023-12-19T00:30:20Z", "aliases": [ "CVE-2023-6355" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1253" + "CWE-1253", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-xp6x-8hgv-x5w5/GHSA-xp6x-8hgv-x5w5.json b/advisories/unreviewed/2023/12/GHSA-xp6x-8hgv-x5w5/GHSA-xp6x-8hgv-x5w5.json index 21ca60df64d..e8a2ac5f979 100644 --- a/advisories/unreviewed/2023/12/GHSA-xp6x-8hgv-x5w5/GHSA-xp6x-8hgv-x5w5.json +++ b/advisories/unreviewed/2023/12/GHSA-xp6x-8hgv-x5w5/GHSA-xp6x-8hgv-x5w5.json @@ -25,6 +25,42 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2023:7886" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0006" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0009" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0010" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0014" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0015" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0016" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0017" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0018" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0020" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6377" diff --git a/advisories/unreviewed/2023/12/GHSA-xqm8-jv67-vcvj/GHSA-xqm8-jv67-vcvj.json b/advisories/unreviewed/2023/12/GHSA-xqm8-jv67-vcvj/GHSA-xqm8-jv67-vcvj.json index 649c75eae51..3101747121e 100644 --- a/advisories/unreviewed/2023/12/GHSA-xqm8-jv67-vcvj/GHSA-xqm8-jv67-vcvj.json +++ b/advisories/unreviewed/2023/12/GHSA-xqm8-jv67-vcvj/GHSA-xqm8-jv67-vcvj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xqm8-jv67-vcvj", - "modified": "2023-12-28T00:30:19Z", + "modified": "2024-01-02T15:30:24Z", "published": "2023-12-21T18:30:22Z", "aliases": [ "CVE-2023-45116" diff --git a/advisories/unreviewed/2024/01/GHSA-47rp-456r-h3xf/GHSA-47rp-456r-h3xf.json b/advisories/unreviewed/2024/01/GHSA-47rp-456r-h3xf/GHSA-47rp-456r-h3xf.json new file mode 100644 index 00000000000..15557df198d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-47rp-456r-h3xf/GHSA-47rp-456r-h3xf.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47rp-456r-h3xf", + "modified": "2024-01-02T15:30:25Z", + "published": "2024-01-02T15:30:25Z", + "aliases": [ + "CVE-2017-20188" + ], + "details": "A vulnerability has been found in Zimbra zm-ajax up to 8.8.1 and classified as problematic. Affected by this vulnerability is the function XFormItem.prototype.setError of the file WebRoot/js/ajax/dwt/xforms/XFormItem.js. The manipulation of the argument message leads to cross site scripting. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 8.8.2 is able to address this issue. The identifier of the patch is 8d039d6efe80780adc40c6f670c06d21de272105. It is recommended to upgrade the affected component. The identifier VDB-249421 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-20188" + }, + { + "type": "WEB", + "url": "https://github.com/Zimbra/zm-ajax/commit/8d039d6efe80780adc40c6f670c06d21de272105" + }, + { + "type": "WEB", + "url": "https://github.com/Zimbra/zm-ajax/releases/tag/8.8.2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249421" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249421" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gwp7-qfff-ww9m/GHSA-gwp7-qfff-ww9m.json b/advisories/unreviewed/2024/01/GHSA-gwp7-qfff-ww9m/GHSA-gwp7-qfff-ww9m.json new file mode 100644 index 00000000000..7b424be04e0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-gwp7-qfff-ww9m/GHSA-gwp7-qfff-ww9m.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwp7-qfff-ww9m", + "modified": "2024-01-02T15:30:25Z", + "published": "2024-01-02T15:30:25Z", + "aliases": [ + "CVE-2024-0188" + ], + "details": "A vulnerability, which was classified as problematic, was found in RRJ Nueva Ecija Engineer Online Portal 1.0. This affects an unknown part of the file change_password_teacher.php. The manipulation leads to weak password requirements. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-249501 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0188" + }, + { + "type": "WEB", + "url": "https://mega.nz/file/2V9ARboA#-JIGiuLxxbri4T1mDEHl8OBeDrwLogoQlLiIji1AQZk" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249501" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249501" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-521" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jx85-225x-qv99/GHSA-jx85-225x-qv99.json b/advisories/unreviewed/2024/01/GHSA-jx85-225x-qv99/GHSA-jx85-225x-qv99.json new file mode 100644 index 00000000000..31a43869af5 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jx85-225x-qv99/GHSA-jx85-225x-qv99.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx85-225x-qv99", + "modified": "2024-01-02T15:30:25Z", + "published": "2024-01-02T15:30:25Z", + "aliases": [ + "CVE-2015-10128" + ], + "details": "A vulnerability was found in rt-prettyphoto Plugin up to 1.2 on WordPress and classified as problematic. Affected by this issue is the function royal_prettyphoto_plugin_links of the file rt-prettyphoto.php. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 1.3 is able to address this issue. The patch is identified as 0d3d38cfa487481b66869e4212df1cefc281ecb7. It is recommended to upgrade the affected component. VDB-249422 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-10128" + }, + { + "type": "WEB", + "url": "https://github.com/wp-plugins/rt-prettyphoto/commit/0d3d38cfa487481b66869e4212df1cefc281ecb7" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249422" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249422" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-r284-mxrr-f624/GHSA-r284-mxrr-f624.json b/advisories/unreviewed/2024/01/GHSA-r284-mxrr-f624/GHSA-r284-mxrr-f624.json new file mode 100644 index 00000000000..1864446e77d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-r284-mxrr-f624/GHSA-r284-mxrr-f624.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r284-mxrr-f624", + "modified": "2024-01-02T15:30:25Z", + "published": "2024-01-02T15:30:25Z", + "aliases": [ + "CVE-2023-6436" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ekol Informatics Website Template allows SQL Injection.This issue affects Website Template: through 20231215.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6436" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-0001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T13:15:08Z" + } +} \ No newline at end of file