mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-23r7-3wvp-5358 GHSA-4m4j-w3qr-4gcc GHSA-5798-fpq9-x4vx GHSA-672h-6x89-76m5 GHSA-9g9h-7mhh-5mcr GHSA-j6r8-x8pp-9mcq GHSA-ppqr-xhhp-8qc5 GHSA-vj62-hww7-72x9
This commit is contained in:
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-23r7-3wvp-5358",
|
||||
"modified": "2023-12-27T00:30:25Z",
|
||||
"published": "2023-12-27T00:30:25Z",
|
||||
"aliases": [
|
||||
"CVE-2023-48003"
|
||||
],
|
||||
"details": "An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv=\"refresh\"' in the WebSocket messages.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48003"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://docs.unsafe-inline.com/0day/asp.net-zero-v12.3.0-html-injection-leads-to-open-redirect-via-websockets-cve-2023-48003"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/passtheticket/vulnerability-research/blob/main/aspnetzero_html_injection_via_websockets_messages.md"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2023-12-26T22:15:13Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4m4j-w3qr-4gcc",
|
||||
"modified": "2023-12-20T18:30:32Z",
|
||||
"modified": "2023-12-27T00:30:25Z",
|
||||
"published": "2023-12-20T18:30:32Z",
|
||||
"aliases": [
|
||||
"CVE-2023-49825"
|
||||
|
||||
@@ -0,0 +1,43 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5798-fpq9-x4vx",
|
||||
"modified": "2023-12-27T00:30:26Z",
|
||||
"published": "2023-12-27T00:30:26Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52096"
|
||||
],
|
||||
"details": "SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (such as when an application receives a StartTransaction Open Charge Point Protocol message with a timestamp parameter of 1000000). This may lead to a SQL exception in applications, and may undermine the integrity of transaction records.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52096"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/steve-community/ocpp-jaxb/issues/13"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/steve-community/steve/issues/1292"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/steve-community/ocpp-jaxb/compare/0.0.7...0.0.8"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2023-12-26T23:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-672h-6x89-76m5",
|
||||
"modified": "2023-12-27T00:30:25Z",
|
||||
"published": "2023-12-27T00:30:25Z",
|
||||
"aliases": [
|
||||
"CVE-2023-49438"
|
||||
],
|
||||
"details": "An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites via a crafted URL by abusing the ?next parameter on the /login and /register routes.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49438"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/Flask-Middleware/flask-security"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/brandon-t-elliott/CVE-2023-49438"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2023-12-26T22:15:13Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9g9h-7mhh-5mcr",
|
||||
"modified": "2023-12-20T21:30:35Z",
|
||||
"modified": "2023-12-27T00:30:25Z",
|
||||
"published": "2023-12-20T21:30:35Z",
|
||||
"aliases": [
|
||||
"CVE-2023-49271"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-j6r8-x8pp-9mcq",
|
||||
"modified": "2023-12-20T21:30:35Z",
|
||||
"modified": "2023-12-27T00:30:25Z",
|
||||
"published": "2023-12-20T21:30:35Z",
|
||||
"aliases": [
|
||||
"CVE-2023-49272"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-ppqr-xhhp-8qc5",
|
||||
"modified": "2023-12-20T21:30:35Z",
|
||||
"modified": "2023-12-27T00:30:25Z",
|
||||
"published": "2023-12-20T21:30:35Z",
|
||||
"aliases": [
|
||||
"CVE-2023-49270"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-vj62-hww7-72x9",
|
||||
"modified": "2023-12-20T18:30:32Z",
|
||||
"modified": "2023-12-27T00:30:25Z",
|
||||
"published": "2023-12-20T18:30:32Z",
|
||||
"aliases": [
|
||||
"CVE-2023-33209"
|
||||
|
||||
Reference in New Issue
Block a user