From 2dbdcccb3cb608bf2c3f186db58f78ea7b782681 Mon Sep 17 00:00:00 2001 From: CVE Team Date: Wed, 9 Feb 2022 21:01:19 +0000 Subject: [PATCH] "-Synchronized-Data." --- 2021/36xxx/CVE-2021-36302.json | 5 +++-- 2022/0xxx/CVE-2022-0552.json | 18 ++++++++++++++++++ 2022/0xxx/CVE-2022-0553.json | 18 ++++++++++++++++++ 2022/22xxx/CVE-2022-22566.json | 5 +++-- 2022/22xxx/CVE-2022-22567.json | 5 +++-- 2022/23xxx/CVE-2022-23616.json | 2 +- 2022/24xxx/CVE-2022-24143.json | 2 +- 7 files changed, 47 insertions(+), 8 deletions(-) create mode 100644 2022/0xxx/CVE-2022-0552.json create mode 100644 2022/0xxx/CVE-2022-0553.json diff --git a/2021/36xxx/CVE-2021-36302.json b/2021/36xxx/CVE-2021-36302.json index f3473ab772d..f09baa4a01d 100644 --- a/2021/36xxx/CVE-2021-36302.json +++ b/2021/36xxx/CVE-2021-36302.json @@ -63,8 +63,9 @@ "references": { "reference_data": [ { - "refsource": "CONFIRM", - "url": "https://www.dell.com/support/kbdoc/en-us/000191165/dsa-2021-178-dell-emc-integrated-solution-for-microsoft-azure-stack-hub-security-update-for-a-just-enough-administration-jea-vulnerability" + "refsource": "MISC", + "url": "https://www.dell.com/support/kbdoc/en-us/000191165/dsa-2021-178-dell-emc-integrated-solution-for-microsoft-azure-stack-hub-security-update-for-a-just-enough-administration-jea-vulnerability", + "name": "https://www.dell.com/support/kbdoc/en-us/000191165/dsa-2021-178-dell-emc-integrated-solution-for-microsoft-azure-stack-hub-security-update-for-a-just-enough-administration-jea-vulnerability" } ] } diff --git a/2022/0xxx/CVE-2022-0552.json b/2022/0xxx/CVE-2022-0552.json new file mode 100644 index 00000000000..f80029fc49f --- /dev/null +++ b/2022/0xxx/CVE-2022-0552.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2022-0552", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file diff --git a/2022/0xxx/CVE-2022-0553.json b/2022/0xxx/CVE-2022-0553.json new file mode 100644 index 00000000000..5fec3a8398f --- /dev/null +++ b/2022/0xxx/CVE-2022-0553.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2022-0553", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file diff --git a/2022/22xxx/CVE-2022-22566.json b/2022/22xxx/CVE-2022-22566.json index ac08d5c47c8..54f200d148e 100644 --- a/2022/22xxx/CVE-2022-22566.json +++ b/2022/22xxx/CVE-2022-22566.json @@ -63,8 +63,9 @@ "references": { "reference_data": [ { - "refsource": "CONFIRM", - "url": "https://www.dell.com/support/kbdoc/en-us/000195905/dsa-2022-028" + "refsource": "MISC", + "url": "https://www.dell.com/support/kbdoc/en-us/000195905/dsa-2022-028", + "name": "https://www.dell.com/support/kbdoc/en-us/000195905/dsa-2022-028" } ] } diff --git a/2022/22xxx/CVE-2022-22567.json b/2022/22xxx/CVE-2022-22567.json index aaaab2002a0..03c606dba2b 100644 --- a/2022/22xxx/CVE-2022-22567.json +++ b/2022/22xxx/CVE-2022-22567.json @@ -63,8 +63,9 @@ "references": { "reference_data": [ { - "refsource": "CONFIRM", - "url": "https://www.dell.com/support/kbdoc/en-us/000195905/dsa-2022-028" + "refsource": "MISC", + "url": "https://www.dell.com/support/kbdoc/en-us/000195905/dsa-2022-028", + "name": "https://www.dell.com/support/kbdoc/en-us/000195905/dsa-2022-028" } ] } diff --git a/2022/23xxx/CVE-2022-23616.json b/2022/23xxx/CVE-2022-23616.json index e7a0a014343..ce44f39793b 100644 --- a/2022/23xxx/CVE-2022-23616.json +++ b/2022/23xxx/CVE-2022-23616.json @@ -35,7 +35,7 @@ "description_data": [ { "lang": "eng", - "value": "XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for an unprivileged user to perform a remote code execution by injecting a groovy script in her own profile and by calling the Reset password feature since the feature is performing a save of the user profile with programming rights in the impacted versions of XWiki. The issue has been patched in XWiki 13.1RC1. There are two different possible workarounds, each consisting of modifying the XWiki/ResetPassword page. 1. The Reset password feature can be entirely disabled by deleting the XWiki/ResetPassword page. 2. The script in XWiki/ResetPassword can also be modified or removed: an administrator can replace it with a simple email contact to ask an administrator to reset the password.\n" + "value": "XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for an unprivileged user to perform a remote code execution by injecting a groovy script in her own profile and by calling the Reset password feature since the feature is performing a save of the user profile with programming rights in the impacted versions of XWiki. The issue has been patched in XWiki 13.1RC1. There are two different possible workarounds, each consisting of modifying the XWiki/ResetPassword page. 1. The Reset password feature can be entirely disabled by deleting the XWiki/ResetPassword page. 2. The script in XWiki/ResetPassword can also be modified or removed: an administrator can replace it with a simple email contact to ask an administrator to reset the password." } ] }, diff --git a/2022/24xxx/CVE-2022-24143.json b/2022/24xxx/CVE-2022-24143.json index 8ce4f380283..07bdd23d4bc 100644 --- a/2022/24xxx/CVE-2022-24143.json +++ b/2022/24xxx/CVE-2022-24143.json @@ -34,7 +34,7 @@ "description_data": [ { "lang": "eng", - "value": "Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the timeZone parameter." + "value": "Tenda AX3 v16.03.12.10_CN and AX12 22.03.01.2_CN was discovered to contain a stack overflow in the function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the timeZone parameter." } ] },