Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-12-05 05:18:23 +00:00
parent 3233cee66e
commit 1adee05199
922 changed files with 1130 additions and 3390 deletions
@@ -8,9 +8,7 @@
],
"summary": "actionpack CRLF injection vulnerability",
"details": "CRLF injection vulnerability in `actionpack/lib/action_controller/response.rb` in Ruby on Rails 2.3.x before 2.3.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the Content-Type header.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,14 +3,10 @@
"id": "GHSA-3988-h75v-hwf6",
"modified": "2022-03-26T00:06:45Z",
"published": "2022-03-26T00:06:45Z",
"aliases": [
],
"aliases": [],
"summary": "Arbitrary shell execution",
"details": "A properly crafted filename would allow for arbitrary code execution when using the --filter=gitmodified command line option",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -47,9 +43,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2022-03-26T00:06:45Z",
@@ -3,14 +3,10 @@
"id": "GHSA-5w9c-rv96-fr7g",
"modified": "2022-03-22T20:33:40Z",
"published": "2022-03-22T19:28:24Z",
"aliases": [
],
"aliases": [],
"summary": "Removal of functional code in faker.js",
"details": "Faker.js helps users create large amounts of data for testing and development. The maintainer deliberately removed the functional code from this package. This appears to be a purposeful and successful attempt to make the package unusable. This is related to the colors.js [CVE-2021-23567](https://github.com/advisories/GHSA-gh88-3pxp-6fm8). \n\nThe functional code for this package was forked and can be found [here](https://github.com/faker-js/faker). ",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -61,9 +57,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2022-03-22T19:28:24Z",
@@ -50,9 +50,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2022-03-30T19:57:38Z",
@@ -3,14 +3,10 @@
"id": "GHSA-mhfv-8rc9-w38c",
"modified": "2022-03-26T00:06:00Z",
"published": "2022-03-26T00:06:00Z",
"aliases": [
],
"aliases": [],
"summary": "Arbitrary shell execution",
"details": "Uses of shell_exec() and exec() were not escaping filenames and configuration settings in most cases",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -47,9 +43,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2022-03-26T00:06:00Z",
@@ -8,9 +8,7 @@
],
"summary": "Drupal vulnerable to Cross-site Scripting",
"details": "Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "TYPO3 Unrestricted File Upload vulnerability",
"details": "TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers to bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -78,9 +78,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-02-28T22:07:55Z",
@@ -8,9 +8,7 @@
],
"summary": "Joomla! Open Redirect vulnerability",
"details": "Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a \"User Redirect Spam fix,\" possibly an open redirect vulnerability.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -85,9 +85,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-02-29T00:01:26Z",
@@ -8,9 +8,7 @@
],
"summary": "Apache Tomcat Path Traversal Vulnerability",
"details": "Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a `RequestDispatcher` is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a `..` (dot dot) in a request parameter.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "Moodle vulnerable to Cross-site scripting",
"details": "The `_bad_protocol_once` function in `phpgwapi/inc/class.kses.inc.php` in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing crafted URL protocols.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "Apache Struts Cross-site Scripting vulnerability",
"details": "Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to \"insufficient quoting of parameters.\"",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -50,9 +50,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2023-04-20T19:07:20Z",
@@ -54,9 +54,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2023-04-24T20:30:55Z",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",

Some files were not shown because too many files have changed in this diff Show More