From 13fc3210fd60260854babe20015825f86dac8df4 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 21 Feb 2025 22:14:54 +0000 Subject: [PATCH] Publish GHSA-qf6m-6m4g-rmrc --- .../09/GHSA-qf6m-6m4g-rmrc/GHSA-qf6m-6m4g-rmrc.json | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2024/09/GHSA-qf6m-6m4g-rmrc/GHSA-qf6m-6m4g-rmrc.json b/advisories/github-reviewed/2024/09/GHSA-qf6m-6m4g-rmrc/GHSA-qf6m-6m4g-rmrc.json index 68f39fc79e4..ee4c4158145 100644 --- a/advisories/github-reviewed/2024/09/GHSA-qf6m-6m4g-rmrc/GHSA-qf6m-6m4g-rmrc.json +++ b/advisories/github-reviewed/2024/09/GHSA-qf6m-6m4g-rmrc/GHSA-qf6m-6m4g-rmrc.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-qf6m-6m4g-rmrc", - "modified": "2024-11-18T16:27:14Z", + "modified": "2025-02-21T22:13:26Z", "published": "2024-09-18T22:06:13Z", "aliases": [ - "CVE-2024-47051" + "CVE-2022-25770" ], "summary": "Mautic has insufficient authentication in upgrade flow", - "details": "### Impact\n\nMautic allows you to update the application via an upgrade script.\n\nThe upgrade logic isn't shielded off correctly, which may lead to vulnerable situation.\n\nThis vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable\n\n### Patches\n\nPlease upgrade to 4.4.1 or 5.1.1 or later.\n\n### Workarounds\nNone.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [security@mautic.org](mailto:security@mautic.org)\n", + "details": "### Impact\n\nMautic allows you to update the application via an upgrade script.\n\nThe upgrade logic isn't shielded off correctly, which may lead to vulnerable situation.\n\nThis vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable\n\n### Patches\n\nPlease upgrade to 4.4.1 or 5.1.1 or later.\n\n### Workarounds\nNone.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [security@mautic.org](mailto:security@mautic.org)", "severity": [ { "type": "CVSS_V3", @@ -101,6 +101,10 @@ "type": "WEB", "url": "https://github.com/mautic/mautic/security/advisories/GHSA-qf6m-6m4g-rmrc" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25770" + }, { "type": "WEB", "url": "https://github.com/mautic/mautic/commit/73b18e9a434a28e528fe0e3d03620e7367bdcdca"