From 0443d5911374f97eada520481de8bc924219787f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 4 Jan 2024 23:10:12 +0000 Subject: [PATCH] Publish GHSA-9gp7-jvm2-r4mx --- .../GHSA-9gp7-jvm2-r4mx.json | 24 +++++++++---------- 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/advisories/github-reviewed/2018/10/GHSA-9gp7-jvm2-r4mx/GHSA-9gp7-jvm2-r4mx.json b/advisories/github-reviewed/2018/10/GHSA-9gp7-jvm2-r4mx/GHSA-9gp7-jvm2-r4mx.json index 94987548154..114c4143073 100644 --- a/advisories/github-reviewed/2018/10/GHSA-9gp7-jvm2-r4mx/GHSA-9gp7-jvm2-r4mx.json +++ b/advisories/github-reviewed/2018/10/GHSA-9gp7-jvm2-r4mx/GHSA-9gp7-jvm2-r4mx.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9gp7-jvm2-r4mx", - "modified": "2021-09-07T21:35:59Z", + "modified": "2024-01-04T23:08:58Z", "published": "2018-10-16T19:36:43Z", "aliases": [ "CVE-2017-7672" ], - "summary": "Moderate severity vulnerability that affects org.apache.struts:struts2-core", + "summary": "Apache Struts Improper Input Validation vulnerability", "details": "If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12.", "severity": [ { @@ -41,8 +41,8 @@ "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-7672" }, { - "type": "ADVISORY", - "url": "https://github.com/advisories/GHSA-9gp7-jvm2-r4mx" + "type": "PACKAGE", + "url": "https://github.com/apache/struts" }, { "type": "WEB", @@ -52,6 +52,14 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20180706-0002/" }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20170907215142/http://www.securitytracker.com/id/1039114" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20200227144724/http://www.securityfocus.com/bid/99563" + }, { "type": "WEB", "url": "http://struts.apache.org/docs/s2-047.html" @@ -59,14 +67,6 @@ { "type": "WEB", "url": "http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/99563" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id/1039114" } ], "database_specific": {