diff --git a/advisories/github-reviewed/2025/01/GHSA-79xx-vf93-p7cx/GHSA-79xx-vf93-p7cx.json b/advisories/github-reviewed/2025/01/GHSA-79xx-vf93-p7cx/GHSA-79xx-vf93-p7cx.json new file mode 100644 index 00000000000..543a0632983 --- /dev/null +++ b/advisories/github-reviewed/2025/01/GHSA-79xx-vf93-p7cx/GHSA-79xx-vf93-p7cx.json @@ -0,0 +1,122 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79xx-vf93-p7cx", + "modified": "2025-01-21T21:09:14Z", + "published": "2025-01-21T21:09:13Z", + "aliases": [ + "CVE-2025-22131" + ], + "summary": "Cross-Site Scripting (XSS) vulnerability in generateNavigation() function in PhpSpreadsheet", + "details": "### Summary\nThe researcher discovered zero-day vulnerability Cross-Site Scripting (XSS) vulnerability in the code which translates the XLSX file into a HTML representation and displays it in the response.\n\n### Details\nWhen generating the HTML from an xlsx file containing multiple sheets, a navigation menu is created. This menu includes the sheet names, which are not sanitized. As a result, an attacker can exploit this vulnerability to execute JavaScript code.\n\n```php\n // Construct HTML\n $html = '';\n\n // Only if there are more than 1 sheets\n if (count($sheets) > 1) {\n // Loop all sheets\n $sheetId = 0;\n\n $html .= '
' . PHP_EOL;\n }\n```\n\n### PoC\n1. Create an XLSX file with multiple sheets : \n\n\n2. Generate the HTML content \n```php\nwriteAllSheets();\n\techo $writer->generateHTMLAll();\n?>\n```\n3. Enjoy\n\n\n\n### Impact\n\nXSS can cause a variety of problems for the end user that range in severity from an annoyance to complete account compromise.\nExample of impacts :\n\n- Disclosure of the user’s session cookie, allowing an attacker to hijack the user’s session and take over the account (Only if HttpOnly cookie's flag is set to false).\n- Redirecting the user to some other page or site (like phishing websites)\n- Modifying the content of the current page (add a fake login page that sends credentials to the attacker).\n- Automatically download malicious files.\n- Requests access to the victim geolocation / camera.\n- ...\n", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "phpoffice/phpspreadsheet" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.0.0" + }, + { + "fixed": "3.8.0" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "phpoffice/phpspreadsheet" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.29.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "phpoffice/phpspreadsheet" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.0.0" + }, + { + "fixed": "2.1.7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "phpoffice/phpspreadsheet" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.2.0" + }, + { + "fixed": "2.3.6" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/PHPOffice/PhpSpreadsheet/security/advisories/GHSA-79xx-vf93-p7cx" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22131" + }, + { + "type": "WEB", + "url": "https://github.com/PHPOffice/PhpSpreadsheet/commit/4088381ccfaf241d7d42c333de0dc8c98e338743" + }, + { + "type": "PACKAGE", + "url": "https://github.com/PHPOffice/PhpSpreadsheet" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-01-21T21:09:13Z", + "nvd_published_at": "2025-01-20T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-c76h-2ccp-4975/GHSA-c76h-2ccp-4975.json b/advisories/github-reviewed/2025/01/GHSA-c76h-2ccp-4975/GHSA-c76h-2ccp-4975.json new file mode 100644 index 00000000000..b486f7afb3c --- /dev/null +++ b/advisories/github-reviewed/2025/01/GHSA-c76h-2ccp-4975/GHSA-c76h-2ccp-4975.json @@ -0,0 +1,123 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c76h-2ccp-4975", + "modified": "2025-01-21T21:10:47Z", + "published": "2025-01-21T21:10:47Z", + "aliases": [ + "CVE-2025-22150" + ], + "summary": "Use of Insufficiently Random Values in undici", + "details": "### Impact\n\n[Undici `fetch()` uses Math.random()](https://github.com/nodejs/undici/blob/8b06b8250907d92fead664b3368f1d2aa27c1f35/lib/web/fetch/body.js#L113) to choose the boundary for a multipart/form-data request. It is known that the output of Math.random() can be predicted if several of its generated values are known.\n\nIf there is a mechanism in an app that sends multipart requests to an attacker-controlled website, they can use this to leak the necessary values. Therefore, An attacker can tamper with the requests going to the backend APIs if certain conditions are met.\n\n### Patches\n\nThis is fixed in 5.28.5; 6.21.1; 7.2.3.\n\n### Workarounds\n\nDo not issue multipart requests to attacker controlled servers.\n\n### References\n\n* https://hackerone.com/reports/2913312\n* https://blog.securityevaluators.com/hacking-the-javascript-lottery-80cc437e3b7f\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "undici" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.5.0" + }, + { + "fixed": "5.28.5" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "npm", + "name": "undici" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "6.0.0" + }, + { + "fixed": "6.21.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "npm", + "name": "undici" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.0.0" + }, + { + "fixed": "7.2.3" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/nodejs/undici/security/advisories/GHSA-c76h-2ccp-4975" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22150" + }, + { + "type": "WEB", + "url": "https://github.com/nodejs/undici/commit/711e20772764c29f6622ddc937c63b6eefdf07d0" + }, + { + "type": "WEB", + "url": "https://github.com/nodejs/undici/commit/c2d78cd19fe4f4c621424491e26ce299e65e934a" + }, + { + "type": "WEB", + "url": "https://github.com/nodejs/undici/commit/c3acc6050b781b827d80c86cbbab34f14458d385" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2913312" + }, + { + "type": "WEB", + "url": "https://blog.securityevaluators.com/hacking-the-javascript-lottery-80cc437e3b7f" + }, + { + "type": "PACKAGE", + "url": "https://github.com/nodejs/undici" + }, + { + "type": "WEB", + "url": "https://github.com/nodejs/undici/blob/8b06b8250907d92fead664b3368f1d2aa27c1f35/lib/web/fetch/body.js#L113" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-330" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-01-21T21:10:47Z", + "nvd_published_at": "2025-01-21T18:15:14Z" + } +} \ No newline at end of file