mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Advisory Database Sync
This commit is contained in:
@@ -8,9 +8,7 @@
|
||||
],
|
||||
"summary": "Jakarta Tomcat cross-site scripting (XSS) vulnerability",
|
||||
"details": "Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
|
||||
@@ -54,9 +54,7 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"cwe_ids": [],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2023-07-31T22:56:15Z",
|
||||
|
||||
@@ -53,9 +53,7 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"cwe_ids": [],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2023-07-13T17:08:08Z",
|
||||
|
||||
@@ -8,9 +8,7 @@
|
||||
],
|
||||
"summary": "Apache Struts Cross-site scripting Vulnerability",
|
||||
"details": "Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
|
||||
@@ -8,9 +8,7 @@
|
||||
],
|
||||
"summary": "Mortbay Jetty Discloses JSP Source Code",
|
||||
"details": "Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash (`%5C`) characters. NOTE: this might be the same issue as CVE-2006-2758.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
|
||||
@@ -8,9 +8,7 @@
|
||||
],
|
||||
"summary": "Missing Cryptographic Step in OWASP Enterprise Security API for Java",
|
||||
"details": "The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attackers to bypass intended cryptographic protection mechanisms via an attack against authenticity in the default configuration, involving a null MAC and a zero MAC length.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
|
||||
@@ -8,9 +8,7 @@
|
||||
],
|
||||
"summary": "Apache Tomcat AJP Connector Information Leak",
|
||||
"details": "The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when \"unsuitable request body data\" is used for a different request, possibly related to Java Servlet pages.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
|
||||
@@ -8,9 +8,7 @@
|
||||
],
|
||||
"summary": "phpMyAdmin CRLF Injection Vulnerability",
|
||||
"details": "CRLF injection vulnerability in phpMyAdmin before 2.6.4-pl4 allows remote attackers to conduct HTTP response splitting attacks via unspecified scripts.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
@@ -55,9 +53,7 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"cwe_ids": [],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2023-09-18T23:46:33Z",
|
||||
|
||||
@@ -3,9 +3,7 @@
|
||||
"id": "GHSA-f36p-42jv-8rh2",
|
||||
"modified": "2022-10-05T22:00:04Z",
|
||||
"published": "2022-09-30T04:53:37Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Lithium vulnerable to Cross Site Scripting in provided Swagger-UI",
|
||||
"details": "### Impact\nA XSS vulnerability in the provided (outdated) Swagger-UI is exploitable in applications using lithium with Swagger-UI enabled.\nThis allows an attacker gain Remote Code Execution (RCE) and potentially exfiltrate secrets in the context of this swagger session.\n\n\n### Patches\nThe used swagger-ui was updated by switching to the latest version of dropwizard-swagger in 8b9b406d608fe482ec0e7adf8705834bca92d7df\n\n\n### Workarounds\nThe risk of injected external content can be reduced by setting up a [Content-Security-Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy).\n\n\n### References\n* https://www.vidocsecurity.com/blog/hacking-swagger-ui-from-xss-to-account-takeovers/\n\n\n### Credits\nWe thank [Mohit Kumar](https://www.linkedin.com/in/mohit-kumar-4ab6b3bb) for reporting this vulnerability!\n",
|
||||
"severity": [
|
||||
|
||||
@@ -3,9 +3,7 @@
|
||||
"id": "GHSA-25gq-jvx2-vg9x",
|
||||
"modified": "2024-05-23T16:59:26Z",
|
||||
"published": "2024-05-23T16:59:25Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Silverstripe X-Forwarded-Host request hostname injection",
|
||||
"details": "A potential hostname injection vulnerability has been found which could allow attackers to alter url resolution.\n\nIf a request contains the X-Forwarded-Host HTTP header a website would then use its value in place of the actual HTTP hostname. In cases where caching is enabled, this could allow an attacker to potentially embed a remote url as the base_url for any site. This would then cause other visitors to the site to be redirected unknowingly.\n\nThis header is necessary for servers running behind a reverse proxy (such as nginx). Such servers are likely not vulnerable to this risk.\n\nA fix has been merged into the default installer, although existing projects which do not run behind a reverse proxy should update their htaccess as below:\n```\n<IfModule mod_headers.c>\n # Remove X-Forwarded-Host header sent as a part of any request from the web\n RequestHeader unset X-Forwarded-Host\n</IfModule>\n```",
|
||||
"severity": [
|
||||
|
||||
@@ -3,9 +3,7 @@
|
||||
"id": "GHSA-2hpc-mf4q-j885",
|
||||
"modified": "2024-05-23T19:19:33Z",
|
||||
"published": "2024-05-23T19:19:33Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Silverstripe CSRF vulnerability in GridFieldAddExistingAutocompleter",
|
||||
"details": "GridField does not have sufficient CSRF protection, meaning that in some cases users with CMS access can be tricked into posting unspecified data into the CMS from external websites. Amongst other default CMS interfaces, GridField is used for management of groups, users and permissions in the CMS.\n\nThe resolution for this issue is to ensure that all gridFieldAlterAction submissions are checked for the SecurityID token during submission.",
|
||||
"severity": [
|
||||
|
||||
@@ -3,9 +3,7 @@
|
||||
"id": "GHSA-34q6-xqxh-gq39",
|
||||
"modified": "2024-05-23T15:21:44Z",
|
||||
"published": "2024-05-23T15:21:44Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Silverstripe XSS In rewritten hash links",
|
||||
"details": "A high level XSS vulnerability has been discovered in the SilverStripe framework which causes links containing hash anchors (E.g. href=\"#anchor\") to be rewritten in an unsafe way.\n\nThe rewriteHashlinks option on SSViewer will rewrite these to contain the current url, although without adequate escaping, meaning that HTML could be injected via injecting unsafe values to any page via the querystring.\n\nDue to the nature of this issue it is likely that a large number of SilverStripe sites are affected.",
|
||||
"severity": [
|
||||
|
||||
@@ -3,9 +3,7 @@
|
||||
"id": "GHSA-4h54-vwx9-3vr3",
|
||||
"modified": "2024-05-23T15:23:50Z",
|
||||
"published": "2024-05-23T15:23:50Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Silverstripe XSS In FormAction",
|
||||
"details": "A cross-site scripting vulnerability has been discovered in the FormAction field where a user-specified title may be specified.",
|
||||
"severity": [
|
||||
|
||||
@@ -3,9 +3,7 @@
|
||||
"id": "GHSA-5f5v-5c3v-gw5v",
|
||||
"modified": "2024-05-23T14:45:11Z",
|
||||
"published": "2024-05-23T14:45:11Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Silverstripe IE requests not properly behaving with rewritehashlinks",
|
||||
"details": "Non IE browsers don’t appear to be affected, but I haven’t tested a wide range of browsers to be sure \n\nRequests that come through from IE do NOT appear to encode all entities in the URL string, meaning they are inserted into output content directly by SSViewer::process() when rewriting hashlinks, as it directly outputs $_SERVER[‘REQUEST_URI’]\n\n**Example IE8 request**\n127.0.0.1 - - [18/Jun/2014:14:13:42 +1000] “GET /site/cars/brands/toyota?one=1\\”onmouseover=\\”alert(‘things’);\\” HTTP/1.1” 200\n\n**Example FF request**\n127.0.0.1 - - [18/Jun/2014:14:14:22 +1000] “GET /site/cars/brands/toyota?one=1\\%22onmouseover=\\%22alert(%27things%27);\\%22 HTTP/1.1” 200\n\nThis causes any hash anchor to have the JS code inserted into the page as-is.",
|
||||
"severity": [
|
||||
|
||||
@@ -3,9 +3,7 @@
|
||||
"id": "GHSA-88jp-9jrv-6368",
|
||||
"modified": "2024-05-23T15:00:45Z",
|
||||
"published": "2024-05-23T15:00:45Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Silverstripe XSS In GridField print",
|
||||
"details": "A cross-site scripting vulnerability has been discovered in the print view of GridField.\n\nThis vulnerability can only be exploited if a user with CMS access has posted malicious or unescaped HTML into any field of an object in a GridField, and the print feature is used.\n\nThis has been resolved by ensuring that the print feature safely escapes all fields.",
|
||||
"severity": [
|
||||
|
||||
@@ -3,9 +3,7 @@
|
||||
"id": "GHSA-f7cq-5v43-8pwp",
|
||||
"modified": "2024-05-23T15:19:41Z",
|
||||
"published": "2024-05-23T15:19:41Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop",
|
||||
"details": "### Impact\n\nThere is a vulnerability in [GO managing malformed DNS message](https://groups.google.com/g/golang-announce/c/wkkO4P9stm0), which impacts Traefik.\nThis vulnerability could be exploited to cause a denial of service.\n\n### References\n\n- [CVE-2024-24788](https://www.cve.org/CVERecord?id=CVE-2024-24788)\n\n### Patches\n\n- https://github.com/traefik/traefik/releases/tag/v2.11.3\n- https://github.com/traefik/traefik/releases/tag/v3.0.1\n\n### Workarounds\n\nNo workaround.\n\n### For more information\n\nIf you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).",
|
||||
"severity": [
|
||||
|
||||
@@ -3,9 +3,7 @@
|
||||
"id": "GHSA-g43w-98wp-m694",
|
||||
"modified": "2024-05-23T14:49:39Z",
|
||||
"published": "2024-05-23T14:49:39Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "SilverStripe framework XML Quadratic Blowup Attack",
|
||||
"details": "A low level vulnerability has been found in the SilverStripe framework, where the Quadratic Blowup Attack could potentially be exploited to affect the performance of a site.\n\nSee http://mashable.com/2014/08/06/wordpress-xml-blowup-dos/ for a writeup.",
|
||||
"severity": [
|
||||
|
||||
@@ -3,9 +3,7 @@
|
||||
"id": "GHSA-hq4p-5mpr-jj9m",
|
||||
"modified": "2024-05-23T17:15:09Z",
|
||||
"published": "2024-05-23T17:15:09Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Silverstripe XSS in dev/build returnURL Parameter",
|
||||
"details": "A XSS risk exists in the returnURL parameter passed to dev/build. An unvalidated url could cause the user to redirect to an unverified third party url outside of the site.\n\nThis issue is resolved in framework 3.1.14 stable release.",
|
||||
"severity": [
|
||||
|
||||
@@ -3,9 +3,7 @@
|
||||
"id": "GHSA-jqp8-v74p-g8px",
|
||||
"modified": "2024-05-23T16:48:11Z",
|
||||
"published": "2024-05-23T16:48:11Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Silverstripe XSS in Director::force_redirect()",
|
||||
"details": "A low level XSS vulnerability has been found in the Framework affecting http redirection via the Director::force_redirect method.\n\nAttempts to redirect to a url may generate HTML which is not safely escaped, and may pose a risk of XSS in some environments.\n\nThis vulnerability is marked low as it is difficult to exploit, as any injected HTML will only be returned from the server if the Location HTTP header is also sent, meaning that any user browsing the site would not be exposed to the body of the response before their browser redirects them.",
|
||||
"severity": [
|
||||
|
||||
@@ -3,9 +3,7 @@
|
||||
"id": "GHSA-mqf5-275h-gf6r",
|
||||
"modified": "2024-05-23T17:27:20Z",
|
||||
"published": "2024-05-23T17:27:19Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Silverstripe framework is vulnerable to XSS in install.php",
|
||||
"details": "During installation, certain parameters (admin_username and admin_password) are not escaped in the setup form.\n\nThis issue is resolved in 3.1.14 stable, although existing users are advised to remove this file prior to deploying to a production server.",
|
||||
"severity": [
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user