Publish Advisories

GHSA-23r7-3wvp-5358
GHSA-4m4j-w3qr-4gcc
GHSA-5798-fpq9-x4vx
GHSA-672h-6x89-76m5
GHSA-9g9h-7mhh-5mcr
GHSA-j6r8-x8pp-9mcq
GHSA-ppqr-xhhp-8qc5
GHSA-vj62-hww7-72x9
This commit is contained in:
advisory-database[bot]
2023-12-27 00:31:42 +00:00
parent fe4aefbb56
commit ff32139165
8 changed files with 126 additions and 5 deletions
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-23r7-3wvp-5358",
"modified": "2023-12-27T00:30:25Z",
"published": "2023-12-27T00:30:25Z",
"aliases": [
"CVE-2023-48003"
],
"details": "An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv=\"refresh\"' in the WebSocket messages.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48003"
},
{
"type": "WEB",
"url": "https://docs.unsafe-inline.com/0day/asp.net-zero-v12.3.0-html-injection-leads-to-open-redirect-via-websockets-cve-2023-48003"
},
{
"type": "WEB",
"url": "https://github.com/passtheticket/vulnerability-research/blob/main/aspnetzero_html_injection_via_websockets_messages.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-26T22:15:13Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4m4j-w3qr-4gcc",
"modified": "2023-12-20T18:30:32Z",
"modified": "2023-12-27T00:30:25Z",
"published": "2023-12-20T18:30:32Z",
"aliases": [
"CVE-2023-49825"
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5798-fpq9-x4vx",
"modified": "2023-12-27T00:30:26Z",
"published": "2023-12-27T00:30:26Z",
"aliases": [
"CVE-2023-52096"
],
"details": "SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (such as when an application receives a StartTransaction Open Charge Point Protocol message with a timestamp parameter of 1000000). This may lead to a SQL exception in applications, and may undermine the integrity of transaction records.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52096"
},
{
"type": "WEB",
"url": "https://github.com/steve-community/ocpp-jaxb/issues/13"
},
{
"type": "WEB",
"url": "https://github.com/steve-community/steve/issues/1292"
},
{
"type": "WEB",
"url": "https://github.com/steve-community/ocpp-jaxb/compare/0.0.7...0.0.8"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-26T23:15:07Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-672h-6x89-76m5",
"modified": "2023-12-27T00:30:25Z",
"published": "2023-12-27T00:30:25Z",
"aliases": [
"CVE-2023-49438"
],
"details": "An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites via a crafted URL by abusing the ?next parameter on the /login and /register routes.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49438"
},
{
"type": "WEB",
"url": "https://github.com/Flask-Middleware/flask-security"
},
{
"type": "WEB",
"url": "https://github.com/brandon-t-elliott/CVE-2023-49438"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-26T22:15:13Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9g9h-7mhh-5mcr",
"modified": "2023-12-20T21:30:35Z",
"modified": "2023-12-27T00:30:25Z",
"published": "2023-12-20T21:30:35Z",
"aliases": [
"CVE-2023-49271"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j6r8-x8pp-9mcq",
"modified": "2023-12-20T21:30:35Z",
"modified": "2023-12-27T00:30:25Z",
"published": "2023-12-20T21:30:35Z",
"aliases": [
"CVE-2023-49272"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ppqr-xhhp-8qc5",
"modified": "2023-12-20T21:30:35Z",
"modified": "2023-12-27T00:30:25Z",
"published": "2023-12-20T21:30:35Z",
"aliases": [
"CVE-2023-49270"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vj62-hww7-72x9",
"modified": "2023-12-20T18:30:32Z",
"modified": "2023-12-27T00:30:25Z",
"published": "2023-12-20T18:30:32Z",
"aliases": [
"CVE-2023-33209"