diff --git a/advisories/unreviewed/2023/12/GHSA-3x3w-849q-423v/GHSA-3x3w-849q-423v.json b/advisories/github-reviewed/2023/12/GHSA-3x3w-849q-423v/GHSA-3x3w-849q-423v.json similarity index 64% rename from advisories/unreviewed/2023/12/GHSA-3x3w-849q-423v/GHSA-3x3w-849q-423v.json rename to advisories/github-reviewed/2023/12/GHSA-3x3w-849q-423v/GHSA-3x3w-849q-423v.json index e3ce229abad..b0a5fb15ef1 100644 --- a/advisories/unreviewed/2023/12/GHSA-3x3w-849q-423v/GHSA-3x3w-849q-423v.json +++ b/advisories/github-reviewed/2023/12/GHSA-3x3w-849q-423v/GHSA-3x3w-849q-423v.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3x3w-849q-423v", - "modified": "2023-12-17T03:30:19Z", + "modified": "2023-12-21T18:24:46Z", "published": "2023-12-17T03:30:19Z", "aliases": [ "CVE-2023-6886" ], + "summary": "Xnx3 Wangmarket Cross-Site Scripting vulnerability", "details": "A vulnerability was found in xnx3 wangmarket 6.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component Role Management Page. The manipulation leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248246 is the identifier assigned to this vulnerability.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "com.xnx3.wangmarket:wangmarket" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "6.1.0" + } + ] + } + ] + } ], "references": [ { @@ -25,6 +44,10 @@ "type": "WEB", "url": "https://github.com/xnx3/wangmarket/issues/8" }, + { + "type": "PACKAGE", + "url": "https://github.com/xnx3/wangmarket" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.248246" @@ -36,11 +59,11 @@ ], "database_specific": { "cwe_ids": [ - "CWE-94" + "CWE-79" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2023-12-21T18:24:46Z", "nvd_published_at": "2023-12-17T01:15:27Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2023/12/GHSA-6qm2-wpxq-7qh2/GHSA-6qm2-wpxq-7qh2.json b/advisories/github-reviewed/2023/12/GHSA-6qm2-wpxq-7qh2/GHSA-6qm2-wpxq-7qh2.json new file mode 100644 index 00000000000..7e522ac00c9 --- /dev/null +++ b/advisories/github-reviewed/2023/12/GHSA-6qm2-wpxq-7qh2/GHSA-6qm2-wpxq-7qh2.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qm2-wpxq-7qh2", + "modified": "2023-12-21T18:24:28Z", + "published": "2023-12-21T18:24:28Z", + "aliases": [ + "CVE-2023-51449" + ], + "summary": "Gradio makes the `/file` secure against file traversal and server-side request forgery attacks", + "details": "Older versions of `gradio` contained a vulnerability in the `/file` route which made them susceptible to file traversal attacks in which an attacker could access arbitrary files on a machine running a Gradio app with a public URL (e.g. if the demo was created with `share=True`, or on Hugging Face Spaces) if they knew the path of files to look for. \n\nThis was not possible through regular URLs passed into a browser, but it was possible through the use of programmatic tools such as `curl` with the `--pass-as-is` flag. \n\nFurthermore, the `/file` route in Gradio apps also contained a vulnerability that made it possible to use it for SSRF attacks.\n\nBoth of these vulnerabilities have been fixed in `gradio==4.11.0`", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "gradio" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.11.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/gradio-app/gradio/security/advisories/GHSA-6qm2-wpxq-7qh2" + }, + { + "type": "WEB", + "url": "https://github.com/gradio-app/gradio/commit/1b9d4234d6c25ef250d882c7b90e1f4039ed2d76" + }, + { + "type": "WEB", + "url": "https://github.com/gradio-app/gradio/commit/7ba8c5da45b004edd12c0460be9222f5b5f5f055" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gradio-app/gradio" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2023-12-21T18:24:28Z", + "nvd_published_at": null + } +} \ No newline at end of file