From 1a0c749416b09a4a67b0e4274a64b2396dc443ed Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 23 Apr 2025 14:38:42 +0000 Subject: [PATCH] Publish Advisories GHSA-pmg2-rph8-p8r6 GHSA-mg8j-w93w-xjgc --- .../2022/12/GHSA-pmg2-rph8-p8r6/GHSA-pmg2-rph8-p8r6.json | 4 ++-- .../2024/08/GHSA-mg8j-w93w-xjgc/GHSA-mg8j-w93w-xjgc.json | 6 +++++- 2 files changed, 7 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2022/12/GHSA-pmg2-rph8-p8r6/GHSA-pmg2-rph8-p8r6.json b/advisories/github-reviewed/2022/12/GHSA-pmg2-rph8-p8r6/GHSA-pmg2-rph8-p8r6.json index 753011cb666..1b62ca8a48f 100644 --- a/advisories/github-reviewed/2022/12/GHSA-pmg2-rph8-p8r6/GHSA-pmg2-rph8-p8r6.json +++ b/advisories/github-reviewed/2022/12/GHSA-pmg2-rph8-p8r6/GHSA-pmg2-rph8-p8r6.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-pmg2-rph8-p8r6", - "modified": "2022-12-20T15:23:21Z", + "modified": "2025-04-23T14:36:30Z", "published": "2022-12-16T00:30:44Z", "aliases": [ "CVE-2022-45969" ], "summary": "Alist vulnerable to Path Traversal", - "details": "In versions of Alist prior to 3.6.0, a user with only file upload permission can bypass the base path restriction by using '... /' to bypass the base path restriction and upload files to an arbitrary path.\n", + "details": "In versions of Alist prior to 3.6.0, a user with only file upload permission can bypass the base path restriction by using '... /' to bypass the base path restriction and upload files to an arbitrary path.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/08/GHSA-mg8j-w93w-xjgc/GHSA-mg8j-w93w-xjgc.json b/advisories/github-reviewed/2024/08/GHSA-mg8j-w93w-xjgc/GHSA-mg8j-w93w-xjgc.json index 24325fee788..5d7214336e5 100644 --- a/advisories/github-reviewed/2024/08/GHSA-mg8j-w93w-xjgc/GHSA-mg8j-w93w-xjgc.json +++ b/advisories/github-reviewed/2024/08/GHSA-mg8j-w93w-xjgc/GHSA-mg8j-w93w-xjgc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mg8j-w93w-xjgc", - "modified": "2024-10-29T14:42:59Z", + "modified": "2025-04-23T14:37:07Z", "published": "2024-08-29T12:31:05Z", "aliases": [ "CVE-2024-45440" @@ -223,6 +223,10 @@ { "type": "WEB", "url": "https://www.drupal.org/project/drupal/releases/11.0.5" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/52266" } ], "database_specific": {