From 961e51f89c88bc0b2dbb5d1ce7c8ab884b34657d Mon Sep 17 00:00:00 2001 From: cad-safe-bot Date: Thu, 23 Nov 2023 21:02:15 +0000 Subject: [PATCH] Auto-Update: 2023-11-23T21:02:12.350298+00:00 --- CVE-2023/CVE-2023-492xx/CVE-2023-49210.json | 28 +++++++++++++++++++++ README.md | 11 ++++---- 2 files changed, 33 insertions(+), 6 deletions(-) create mode 100644 CVE-2023/CVE-2023-492xx/CVE-2023-49210.json diff --git a/CVE-2023/CVE-2023-492xx/CVE-2023-49210.json b/CVE-2023/CVE-2023-492xx/CVE-2023-49210.json new file mode 100644 index 00000000000..3226b44e7ab --- /dev/null +++ b/CVE-2023/CVE-2023-492xx/CVE-2023-49210.json @@ -0,0 +1,28 @@ +{ + "id": "CVE-2023-49210", + "sourceIdentifier": "cve@mitre.org", + "published": "2023-11-23T20:15:07.157", + "lastModified": "2023-11-23T20:15:07.157", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as \"a nonsense wrapper with no real purpose\" by its author, and accepts an opts argument that contains a verb field (used for command execution). NOTE: This vulnerability only affects products that are no longer supported by the maintainer." + } + ], + "metrics": {}, + "references": [ + { + "url": "https://gist.github.com/mcoimbra/b05a55a5760172dccaa0a827647ad63e", + "source": "cve@mitre.org" + }, + { + "url": "https://github.com/ossf/malicious-packages/tree/main/malicious/npm", + "source": "cve@mitre.org" + }, + { + "url": "https://www.npmjs.com/package/openssl", + "source": "cve@mitre.org" + } + ] +} \ No newline at end of file diff --git a/README.md b/README.md index e2202ced59a..af9d1e3ace0 100644 --- a/README.md +++ b/README.md @@ -9,13 +9,13 @@ Repository synchronizes with the NVD every 2 hours. ### Last Repository Update ```plain -2023-11-23T19:01:02.537193+00:00 +2023-11-23T21:02:12.350298+00:00 ``` ### Most recent CVE Modification Timestamp synchronized with NVD ```plain -2023-11-23T18:15:07.470000+00:00 +2023-11-23T20:15:07.157000+00:00 ``` ### Last Data Feed Release @@ -29,15 +29,14 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/ ### Total Number of included CVEs ```plain -231459 +231460 ``` ### CVEs added in the last Commit -Recently added CVEs: `2` +Recently added CVEs: `1` -* [CVE-2023-49208](CVE-2023/CVE-2023-492xx/CVE-2023-49208.json) (`2023-11-23T18:15:07.410`) -* [CVE-2023-5972](CVE-2023/CVE-2023-59xx/CVE-2023-5972.json) (`2023-11-23T18:15:07.470`) +* [CVE-2023-49210](CVE-2023/CVE-2023-492xx/CVE-2023-49210.json) (`2023-11-23T20:15:07.157`) ### CVEs modified in the last Commit