mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-2fx5-pggv-6jjr GHSA-7cmp-cgg8-4c82 GHSA-ff6q-3c9c-6cf5 GHSA-w8xv-rwgf-4fwh
This commit is contained in:
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2fx5-pggv-6jjr",
|
||||
"modified": "2025-01-14T22:00:32Z",
|
||||
"modified": "2025-01-15T15:26:55Z",
|
||||
"published": "2025-01-14T15:24:20Z",
|
||||
"aliases": [
|
||||
"CVE-2024-55892"
|
||||
],
|
||||
"summary": "TYPO3 Potential Open Redirect via Parsing Differences",
|
||||
"details": "### Problem\nApplications that use `TYPO3\\CMS\\Core\\Http\\Uri` to parse externally provided URLs (e.g., via a query parameter) and validate the host of the parsed URL may be vulnerable to open redirect or SSRF attacks if the URL is used after passing the validation checks.\n\n### Solution\nUpdate to TYPO3 versions 9.5.49 ELTS, 10.4.48 ELTS, 11.5.42 ELTS, 12.4.25 LTS, 13.4.3 LTS that fix the problem described.\n\n### Credits\nThanks to Sam Mush who reported this issue and to TYPO3 core & security team member Benjamin Franzke who fixed the issue.\n\n### References\n* [TYPO3-CORE-SA-2025-002](https://typo3.org/security/advisory/typo3-core-sa-2025-002)\n",
|
||||
"details": "### Problem\nApplications that use `TYPO3\\CMS\\Core\\Http\\Uri` to parse externally provided URLs (e.g., via a query parameter) and validate the host of the parsed URL may be vulnerable to open redirect or SSRF attacks if the URL is used after passing the validation checks.\n\n### Solution\nUpdate to TYPO3 versions 9.5.49 ELTS, 10.4.48 ELTS, 11.5.42 ELTS, 12.4.25 LTS, 13.4.3 LTS that fix the problem described.\n\n### Credits\nThanks to Sam Mush and Christian Eßl who reported this issue and to TYPO3 core & security team member Benjamin Franzke who fixed the issue.\n\n### References\n* [TYPO3-CORE-SA-2025-002](https://typo3.org/security/advisory/typo3-core-sa-2025-002)\n",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7cmp-cgg8-4c82",
|
||||
"modified": "2025-01-14T23:04:40Z",
|
||||
"modified": "2025-01-15T15:25:45Z",
|
||||
"published": "2025-01-14T22:18:52Z",
|
||||
"aliases": [
|
||||
"CVE-2024-47605"
|
||||
@@ -40,6 +40,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/silverstripe/silverstripe-asset-admin/security/advisories/GHSA-7cmp-cgg8-4c82"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47605"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/silverstripe/silverstripe-framework/commit/09b5052c86932f273e0d733428c9aade70ff2a4a"
|
||||
@@ -60,6 +64,6 @@
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2025-01-14T22:18:52Z",
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2025-01-14T23:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-ff6q-3c9c-6cf5",
|
||||
"modified": "2025-01-14T22:58:37Z",
|
||||
"modified": "2025-01-15T15:25:53Z",
|
||||
"published": "2025-01-14T22:18:59Z",
|
||||
"aliases": [
|
||||
"CVE-2024-53277"
|
||||
@@ -40,6 +40,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/silverstripe/silverstripe-framework/security/advisories/GHSA-ff6q-3c9c-6cf5"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53277"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/silverstripe/silverstripe-framework/commit/74904f539347b7d1f8c5b5fb9e28d62ff251ee00"
|
||||
@@ -60,6 +64,6 @@
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2025-01-14T22:18:59Z",
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2025-01-14T23:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-w8xv-rwgf-4fwh",
|
||||
"modified": "2025-01-14T16:32:07Z",
|
||||
"modified": "2025-01-15T15:26:01Z",
|
||||
"published": "2025-01-14T16:32:07Z",
|
||||
"aliases": [
|
||||
"CVE-2025-0343"
|
||||
@@ -38,6 +38,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/apple/swift-asn1/security/advisories/GHSA-w8xv-rwgf-4fwh"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0343"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/apple/swift-asn1/commit/ae33e5941bb88d88538d0a6b19ca0b01e6c76dcf"
|
||||
@@ -54,6 +58,6 @@
|
||||
"severity": "LOW",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2025-01-14T16:32:07Z",
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2025-01-15T01:15:13Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user