Skip to content

Commit

Permalink
generated content from 2025-01-13
Browse files Browse the repository at this point in the history
  • Loading branch information
gitadvisor committed Jan 13, 2025
1 parent d37205b commit 331bc89
Show file tree
Hide file tree
Showing 24 changed files with 529 additions and 0 deletions.
23 changes: 23 additions & 0 deletions mapping.csv
Original file line number Diff line number Diff line change
Expand Up @@ -263120,3 +263120,26 @@ vulnerability,CVE-2025-22617,vulnerability--be65c524-58aa-453c-8e23-6cc258630cc5
vulnerability,CVE-2025-22616,vulnerability--0c4bf6ed-8ef0-4659-893c-7e76ceaae251
vulnerability,CVE-2025-22618,vulnerability--1a9aa62c-a235-4613-b509-d101fe4eab35
vulnerability,CVE-2025-22619,vulnerability--c24281cb-c1e5-4bbb-98b2-8c289beaa22b
vulnerability,CVE-2023-42241,vulnerability--77c46ef6-34de-4bdf-b8d6-bfa53a2986d8
vulnerability,CVE-2023-42245,vulnerability--e9c62422-5140-4663-b42e-0699390400ff
vulnerability,CVE-2023-42239,vulnerability--295f2fbb-cd8c-4073-8c15-ee9eccdc000b
vulnerability,CVE-2023-42243,vulnerability--2cf8f27a-3824-4482-9be8-ae30f494bbea
vulnerability,CVE-2023-42234,vulnerability--9476b093-0302-4134-b305-be7454c4bc1e
vulnerability,CVE-2023-42248,vulnerability--1037ef38-4767-4627-925f-af3395159df9
vulnerability,CVE-2023-42242,vulnerability--06ce959a-7a4a-4d6e-b95b-867815f89b5c
vulnerability,CVE-2023-42235,vulnerability--1e0f1faf-e1f4-455e-9658-ef246a66f104
vulnerability,CVE-2023-42249,vulnerability--6cc2f440-b98a-49bc-90f0-1e1a33106539
vulnerability,CVE-2023-42240,vulnerability--708a1967-c181-4e30-98c4-201de1270c1a
vulnerability,CVE-2023-42246,vulnerability--e401305d-d7d0-4324-abf5-2da67c786ffd
vulnerability,CVE-2023-42250,vulnerability--66bb21b4-e6d9-4100-8b23-4122aefeb181
vulnerability,CVE-2023-42233,vulnerability--f09966f9-a26a-40b4-b573-25789c1f1fbe
vulnerability,CVE-2023-42236,vulnerability--829fc0f3-f429-4bad-a3ec-0658254365a3
vulnerability,CVE-2023-42238,vulnerability--e16ed311-0615-449f-a366-7bed6ed37230
vulnerability,CVE-2023-42247,vulnerability--26627969-a5f2-4f4e-a644-ccef761afc17
vulnerability,CVE-2023-42244,vulnerability--2cfb84d2-44a1-48dd-8df0-5836f89b2caf
vulnerability,CVE-2023-42237,vulnerability--632d0b42-33ae-4822-a8fd-c3e5fd1f6dba
vulnerability,CVE-2024-11128,vulnerability--a3370eea-5a53-42eb-80a0-5a7fb528bcae
vulnerability,CVE-2024-56138,vulnerability--310d8a33-d2fd-473a-be58-152ebdf8e744
vulnerability,CVE-2024-56323,vulnerability--bc72cab1-81d0-428c-918a-24d89f6c7f46
vulnerability,CVE-2024-57811,vulnerability--ad176bda-2060-459d-b9a5-004fa53ae6f0
vulnerability,CVE-2024-51491,vulnerability--e368db9c-4e80-4c47-a881-637ba77ddf6a
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--d991cc30-a566-433d-ab35-3b34cc7c9c1d",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--06ce959a-7a4a-4d6e-b95b-867815f89b5c",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2025-01-13T22:17:41.290977Z",
"modified": "2025-01-13T22:17:41.290977Z",
"name": "CVE-2023-42242",
"description": "An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /monitor/s_terminal.php.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2023-42242"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--04f507f7-c800-4d50-aee2-a9b5e5be3f11",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--1037ef38-4767-4627-925f-af3395159df9",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2025-01-13T22:17:41.281926Z",
"modified": "2025-01-13T22:17:41.281926Z",
"name": "CVE-2023-42248",
"description": "An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbitrary files by manipulating POST parameters of the page \"common/vam_Sql.php\".",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2023-42248"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--96af7f21-f6a0-45fb-a657-7cd0fd4a7298",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--1e0f1faf-e1f4-455e-9658-ef246a66f104",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2025-01-13T22:17:41.292875Z",
"modified": "2025-01-13T22:17:41.292875Z",
"name": "CVE-2023-42235",
"description": "An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple parameters of /monitor/s_normalizedtrans.php.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2023-42235"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--95bb21bc-adba-49cd-a1fa-bbba97086d1d",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--26627969-a5f2-4f4e-a644-ccef761afc17",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2025-01-13T22:17:41.318473Z",
"modified": "2025-01-13T22:17:41.318473Z",
"name": "CVE-2023-42247",
"description": "Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_monitor_map.php.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2023-42247"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--16c60fd8-805c-4b06-a8e2-67527fc460ad",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--295f2fbb-cd8c-4073-8c15-ee9eccdc000b",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2025-01-13T22:17:41.27502Z",
"modified": "2025-01-13T22:17:41.27502Z",
"name": "CVE-2023-42239",
"description": "An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_ep.php.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2023-42239"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--d2ec4e31-2ae5-46c4-9d1b-26dc3160ee7a",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--2cf8f27a-3824-4482-9be8-ae30f494bbea",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2025-01-13T22:17:41.276222Z",
"modified": "2025-01-13T22:17:41.276222Z",
"name": "CVE-2023-42243",
"description": "In Selesta Visual Access Manager < 4.42.2, an authenticated user can access the administrative page /common/vam_Sql.php, which allows for arbitrary SQL queries.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2023-42243"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--bb5f914b-d831-4ff3-b90f-529f080108fd",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--2cfb84d2-44a1-48dd-8df0-5836f89b2caf",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2025-01-13T22:17:41.320548Z",
"modified": "2025-01-13T22:17:41.320548Z",
"name": "CVE-2023-42244",
"description": "An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_visits.php.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2023-42244"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--bd75574c-771d-400e-b8a1-6421da8dac86",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--310d8a33-d2fd-473a-be58-152ebdf8e744",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2025-01-13T22:17:43.767078Z",
"modified": "2025-01-13T22:17:43.767078Z",
"name": "CVE-2024-56138",
"description": "notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. This issue was identified during Quarkslab's audit of the timestamp feature. During the timestamp signature generation, the revocation status of the certificate(s) used to generate the timestamp signature was not verified. During timestamp signature generation, notation-go did not check the revocation status of the certificate chain used by the TSA. This oversight creates a vulnerability that could be exploited through a Man-in-The-Middle attack. An attacker could potentially use a compromised, intermediate, or revoked leaf certificate to generate a malicious countersignature, which would then be accepted and stored by `notation`. This could lead to denial of service scenarios, particularly in CI/CD environments during signature verification processes because timestamp signature would fail due to the presence of a revoked certificate(s) potentially disrupting operations. This issue has been addressed in release version 1.3.0-rc.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2024-56138"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--37114a32-746a-4c85-b58c-82257fa2d5ea",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--632d0b42-33ae-4822-a8fd-c3e5fd1f6dba",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2025-01-13T22:17:41.327275Z",
"modified": "2025-01-13T22:17:41.327275Z",
"name": "CVE-2023-42237",
"description": "An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple GET parameters of /vam/vam_i_command.php.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2023-42237"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--4d43ce07-4cb3-44aa-8aa8-b3733835d179",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--66bb21b4-e6d9-4100-8b23-4122aefeb181",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2025-01-13T22:17:41.303183Z",
"modified": "2025-01-13T22:17:41.303183Z",
"name": "CVE-2023-42250",
"description": "Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /common/autocomplete.php.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2023-42250"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--14a07209-5723-4215-b8dd-dbaba8beca2f",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--6cc2f440-b98a-49bc-90f0-1e1a33106539",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2025-01-13T22:17:41.296384Z",
"modified": "2025-01-13T22:17:41.296384Z",
"name": "CVE-2023-42249",
"description": "Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via vam/vam_visits.php.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2023-42249"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--d63c2d94-de32-46b5-9dde-94489f65d9ae",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--708a1967-c181-4e30-98c4-201de1270c1a",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2025-01-13T22:17:41.298801Z",
"modified": "2025-01-13T22:17:41.298801Z",
"name": "CVE-2023-42240",
"description": "An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /monitor/s_scheduledfile.php.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2023-42240"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--b900f74a-224d-4825-9fa5-9f5e489aee5e",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--77c46ef6-34de-4bdf-b8d6-bfa53a2986d8",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2025-01-13T22:17:41.264177Z",
"modified": "2025-01-13T22:17:41.264177Z",
"name": "CVE-2023-42241",
"description": "An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_anagraphic.php.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2023-42241"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--0d57fff7-679b-43a2-9327-2b5a90dcccf2",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--829fc0f3-f429-4bad-a3ec-0658254365a3",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2025-01-13T22:17:41.315997Z",
"modified": "2025-01-13T22:17:41.315997Z",
"name": "CVE-2023-42236",
"description": "An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /common/ajaxfunction.php.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2023-42236"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--7f1ccb4e-64bb-4e3e-b9f6-138a12deb25d",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--9476b093-0302-4134-b305-be7454c4bc1e",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2025-01-13T22:17:41.277813Z",
"modified": "2025-01-13T22:17:41.277813Z",
"name": "CVE-2023-42234",
"description": "Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView function.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2023-42234"
}
]
}
]
}
Loading

0 comments on commit 331bc89

Please sign in to comment.