From 1e2de3e7e6914a218492a9059520dcb21a58cbc2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 11 Jan 2024 19:30:24 +0000 Subject: [PATCH] Publish Advisories GHSA-269w-pqc7-68q9 GHSA-792f-c8mp-2cr5 GHSA-crjc-2v9m-8w7r GHSA-h4xc-577p-hgj9 GHSA-jwxh-wj79-ccm6 GHSA-w2p4-2c8c-2g7h GHSA-269w-pqc7-68q9 GHSA-792f-c8mp-2cr5 GHSA-crjc-2v9m-8w7r GHSA-h4xc-577p-hgj9 GHSA-jwxh-wj79-ccm6 GHSA-w2p4-2c8c-2g7h --- .../GHSA-269w-pqc7-68q9.json | 88 +++++++++++++++++++ .../GHSA-792f-c8mp-2cr5.json | 88 +++++++++++++++++++ .../GHSA-crjc-2v9m-8w7r.json | 88 +++++++++++++++++++ .../GHSA-h4xc-577p-hgj9.json | 88 +++++++++++++++++++ .../GHSA-jwxh-wj79-ccm6.json | 88 +++++++++++++++++++ .../GHSA-w2p4-2c8c-2g7h.json | 88 +++++++++++++++++++ .../GHSA-269w-pqc7-68q9.json | 35 -------- .../GHSA-792f-c8mp-2cr5.json | 35 -------- .../GHSA-crjc-2v9m-8w7r.json | 38 -------- .../GHSA-h4xc-577p-hgj9.json | 35 -------- .../GHSA-jwxh-wj79-ccm6.json | 35 -------- .../GHSA-w2p4-2c8c-2g7h.json | 35 -------- 12 files changed, 528 insertions(+), 213 deletions(-) create mode 100644 advisories/github-reviewed/2022/05/GHSA-269w-pqc7-68q9/GHSA-269w-pqc7-68q9.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-792f-c8mp-2cr5/GHSA-792f-c8mp-2cr5.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-crjc-2v9m-8w7r/GHSA-crjc-2v9m-8w7r.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-h4xc-577p-hgj9/GHSA-h4xc-577p-hgj9.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-jwxh-wj79-ccm6/GHSA-jwxh-wj79-ccm6.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-w2p4-2c8c-2g7h/GHSA-w2p4-2c8c-2g7h.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-269w-pqc7-68q9/GHSA-269w-pqc7-68q9.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-792f-c8mp-2cr5/GHSA-792f-c8mp-2cr5.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-crjc-2v9m-8w7r/GHSA-crjc-2v9m-8w7r.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-h4xc-577p-hgj9/GHSA-h4xc-577p-hgj9.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-jwxh-wj79-ccm6/GHSA-jwxh-wj79-ccm6.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-w2p4-2c8c-2g7h/GHSA-w2p4-2c8c-2g7h.json diff --git a/advisories/github-reviewed/2022/05/GHSA-269w-pqc7-68q9/GHSA-269w-pqc7-68q9.json b/advisories/github-reviewed/2022/05/GHSA-269w-pqc7-68q9/GHSA-269w-pqc7-68q9.json new file mode 100644 index 00000000000..8c30c722526 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-269w-pqc7-68q9/GHSA-269w-pqc7-68q9.json @@ -0,0 +1,88 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-269w-pqc7-68q9", + "modified": "2024-01-11T19:29:52Z", + "published": "2022-05-24T17:41:55Z", + "aliases": [ + "CVE-2021-21014" + ], + "summary": "Magento vulnerable to a file upload restriction bypass", + "details": "Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.3.6-p1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.0" + }, + { + "fixed": "2.4.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21014" + }, + { + "type": "WEB", + "url": "https://github.com/magento/magento2/commit/a2eb7e29ea92a8bbc86c3b6b81b59d8533088497" + }, + { + "type": "WEB", + "url": "https://github.com/magento/magento2/commit/a349e022c9ae070e7da262021f9ef182105aa00b" + }, + { + "type": "PACKAGE", + "url": "https://github.com/magento/magento2" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb21-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-01-11T19:29:52Z", + "nvd_published_at": "2021-02-11T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-792f-c8mp-2cr5/GHSA-792f-c8mp-2cr5.json b/advisories/github-reviewed/2022/05/GHSA-792f-c8mp-2cr5/GHSA-792f-c8mp-2cr5.json new file mode 100644 index 00000000000..a8251851789 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-792f-c8mp-2cr5/GHSA-792f-c8mp-2cr5.json @@ -0,0 +1,88 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-792f-c8mp-2cr5", + "modified": "2024-01-11T19:29:47Z", + "published": "2022-05-24T17:41:54Z", + "aliases": [ + "CVE-2021-21016" + ], + "summary": "Magento OS command injection via the WebAPI", + "details": "Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the WebAPI. Successful exploitation could lead to remote code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.3.6-p1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.0" + }, + { + "fixed": "2.4.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21016" + }, + { + "type": "WEB", + "url": "https://github.com/magento/magento2/commit/a2eb7e29ea92a8bbc86c3b6b81b59d8533088497" + }, + { + "type": "WEB", + "url": "https://github.com/magento/magento2/commit/a349e022c9ae070e7da262021f9ef182105aa00b" + }, + { + "type": "PACKAGE", + "url": "https://github.com/magento/magento2" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb21-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-01-11T19:29:47Z", + "nvd_published_at": "2021-02-11T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-crjc-2v9m-8w7r/GHSA-crjc-2v9m-8w7r.json b/advisories/github-reviewed/2022/05/GHSA-crjc-2v9m-8w7r/GHSA-crjc-2v9m-8w7r.json new file mode 100644 index 00000000000..b81dac6e742 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-crjc-2v9m-8w7r/GHSA-crjc-2v9m-8w7r.json @@ -0,0 +1,88 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crjc-2v9m-8w7r", + "modified": "2024-01-11T19:29:40Z", + "published": "2022-05-24T17:41:56Z", + "aliases": [ + "CVE-2021-21026" + ], + "summary": "Magento improper authorization vulnerability in the integrations module", + "details": "Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by an improper authorization vulnerability in the integrations module. Successful exploitation could lead to unauthorized access to restricted resources by an unauthenticated attacker. Access to the admin console is required for successful exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.3.6-p1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.0" + }, + { + "fixed": "2.4.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21026" + }, + { + "type": "WEB", + "url": "https://github.com/magento/magento2/commit/a2eb7e29ea92a8bbc86c3b6b81b59d8533088497" + }, + { + "type": "WEB", + "url": "https://github.com/magento/magento2/commit/a349e022c9ae070e7da262021f9ef182105aa00b" + }, + { + "type": "PACKAGE", + "url": "https://github.com/magento/magento2" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb21-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-01-11T19:29:40Z", + "nvd_published_at": "2021-02-11T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-h4xc-577p-hgj9/GHSA-h4xc-577p-hgj9.json b/advisories/github-reviewed/2022/05/GHSA-h4xc-577p-hgj9/GHSA-h4xc-577p-hgj9.json new file mode 100644 index 00000000000..2489fca4da7 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-h4xc-577p-hgj9/GHSA-h4xc-577p-hgj9.json @@ -0,0 +1,88 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4xc-577p-hgj9", + "modified": "2024-01-11T19:29:35Z", + "published": "2022-05-24T17:41:56Z", + "aliases": [ + "CVE-2021-21027" + ], + "summary": "Magento cross-site request forgery (CSRF) vulnerability via the GraphQL API", + "details": "Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via the GraphQL API. Successful exploitation could lead to unauthorized modification of customer metadata by an unauthenticated attacker. Access to the admin console is not required for successful exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.3.6-p1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.0" + }, + { + "fixed": "2.4.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21027" + }, + { + "type": "WEB", + "url": "https://github.com/magento/magento2/commit/a2eb7e29ea92a8bbc86c3b6b81b59d8533088497" + }, + { + "type": "WEB", + "url": "https://github.com/magento/magento2/commit/a349e022c9ae070e7da262021f9ef182105aa00b" + }, + { + "type": "PACKAGE", + "url": "https://github.com/magento/magento2" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb21-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-01-11T19:29:35Z", + "nvd_published_at": "2021-02-11T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-jwxh-wj79-ccm6/GHSA-jwxh-wj79-ccm6.json b/advisories/github-reviewed/2022/05/GHSA-jwxh-wj79-ccm6/GHSA-jwxh-wj79-ccm6.json new file mode 100644 index 00000000000..08965295de5 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-jwxh-wj79-ccm6/GHSA-jwxh-wj79-ccm6.json @@ -0,0 +1,88 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwxh-wj79-ccm6", + "modified": "2024-01-11T19:29:29Z", + "published": "2022-05-24T17:41:56Z", + "aliases": [ + "CVE-2021-21029" + ], + "summary": "Magento Reflected Cross-site Scripting vulnerability via 'file' parameter", + "details": "Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulnerability via 'file' parameter. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Access to the admin console is required for successful exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.3.6-p1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.0" + }, + { + "fixed": "2.4.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21029" + }, + { + "type": "WEB", + "url": "https://github.com/magento/magento2/commit/a2eb7e29ea92a8bbc86c3b6b81b59d8533088497" + }, + { + "type": "WEB", + "url": "https://github.com/magento/magento2/commit/a349e022c9ae070e7da262021f9ef182105aa00b" + }, + { + "type": "PACKAGE", + "url": "https://github.com/magento/magento2" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb21-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-01-11T19:29:29Z", + "nvd_published_at": "2021-02-11T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-w2p4-2c8c-2g7h/GHSA-w2p4-2c8c-2g7h.json b/advisories/github-reviewed/2022/05/GHSA-w2p4-2c8c-2g7h/GHSA-w2p4-2c8c-2g7h.json new file mode 100644 index 00000000000..fe7707c30f5 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-w2p4-2c8c-2g7h/GHSA-w2p4-2c8c-2g7h.json @@ -0,0 +1,88 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2p4-2c8c-2g7h", + "modified": "2024-01-11T19:29:24Z", + "published": "2022-05-24T17:41:54Z", + "aliases": [ + "CVE-2021-21015" + ], + "summary": "Magento OS command injection via the customer attribute save controller", + "details": "Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an OS command injection via the customer attribute save controller. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.3.6-p1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.0" + }, + { + "fixed": "2.4.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21015" + }, + { + "type": "WEB", + "url": "https://github.com/magento/magento2/commit/a2eb7e29ea92a8bbc86c3b6b81b59d8533088497" + }, + { + "type": "WEB", + "url": "https://github.com/magento/magento2/commit/a349e022c9ae070e7da262021f9ef182105aa00b" + }, + { + "type": "PACKAGE", + "url": "https://github.com/magento/magento2" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb21-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-01-11T19:29:24Z", + "nvd_published_at": "2021-02-11T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-269w-pqc7-68q9/GHSA-269w-pqc7-68q9.json b/advisories/unreviewed/2022/05/GHSA-269w-pqc7-68q9/GHSA-269w-pqc7-68q9.json deleted file mode 100644 index 769e5540576..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-269w-pqc7-68q9/GHSA-269w-pqc7-68q9.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-269w-pqc7-68q9", - "modified": "2022-05-24T17:41:55Z", - "published": "2022-05-24T17:41:55Z", - "aliases": [ - "CVE-2021-21014" - ], - "details": "Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21014" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb21-08.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-434" - ], - "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2021-02-11T21:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-792f-c8mp-2cr5/GHSA-792f-c8mp-2cr5.json b/advisories/unreviewed/2022/05/GHSA-792f-c8mp-2cr5/GHSA-792f-c8mp-2cr5.json deleted file mode 100644 index b08662f1703..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-792f-c8mp-2cr5/GHSA-792f-c8mp-2cr5.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-792f-c8mp-2cr5", - "modified": "2022-05-24T17:41:54Z", - "published": "2022-05-24T17:41:54Z", - "aliases": [ - "CVE-2021-21016" - ], - "details": "Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the WebAPI. Successful exploitation could lead to remote code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21016" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb21-08.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-78" - ], - "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2021-02-11T20:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-crjc-2v9m-8w7r/GHSA-crjc-2v9m-8w7r.json b/advisories/unreviewed/2022/05/GHSA-crjc-2v9m-8w7r/GHSA-crjc-2v9m-8w7r.json deleted file mode 100644 index e001a1140dc..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-crjc-2v9m-8w7r/GHSA-crjc-2v9m-8w7r.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-crjc-2v9m-8w7r", - "modified": "2022-10-22T12:00:27Z", - "published": "2022-05-24T17:41:56Z", - "aliases": [ - "CVE-2021-21026" - ], - "details": "Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by an improper authorization vulnerability in the integrations module. Successful exploitation could lead to unauthorized access to restricted resources by an unauthenticated attacker. Access to the admin console is required for successful exploitation.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21026" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb21-08.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-285" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2021-02-11T20:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-h4xc-577p-hgj9/GHSA-h4xc-577p-hgj9.json b/advisories/unreviewed/2022/05/GHSA-h4xc-577p-hgj9/GHSA-h4xc-577p-hgj9.json deleted file mode 100644 index ef8d3243727..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-h4xc-577p-hgj9/GHSA-h4xc-577p-hgj9.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-h4xc-577p-hgj9", - "modified": "2022-05-24T17:41:56Z", - "published": "2022-05-24T17:41:56Z", - "aliases": [ - "CVE-2021-21027" - ], - "details": "Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via the GraphQL API. Successful exploitation could lead to unauthorized modification of customer metadata by an unauthenticated attacker. Access to the admin console is not required for successful exploitation.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21027" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb21-08.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-352" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2021-02-11T20:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-jwxh-wj79-ccm6/GHSA-jwxh-wj79-ccm6.json b/advisories/unreviewed/2022/05/GHSA-jwxh-wj79-ccm6/GHSA-jwxh-wj79-ccm6.json deleted file mode 100644 index 6e376da20e5..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-jwxh-wj79-ccm6/GHSA-jwxh-wj79-ccm6.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-jwxh-wj79-ccm6", - "modified": "2022-05-24T17:41:56Z", - "published": "2022-05-24T17:41:56Z", - "aliases": [ - "CVE-2021-21029" - ], - "details": "Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulnerability via 'file' parameter. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Access to the admin console is required for successful exploitation.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21029" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb21-08.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2021-02-11T20:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-w2p4-2c8c-2g7h/GHSA-w2p4-2c8c-2g7h.json b/advisories/unreviewed/2022/05/GHSA-w2p4-2c8c-2g7h/GHSA-w2p4-2c8c-2g7h.json deleted file mode 100644 index 44313b5c6c5..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-w2p4-2c8c-2g7h/GHSA-w2p4-2c8c-2g7h.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-w2p4-2c8c-2g7h", - "modified": "2022-05-24T17:41:54Z", - "published": "2022-05-24T17:41:54Z", - "aliases": [ - "CVE-2021-21015" - ], - "details": "Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an OS command injection via the customer attribute save controller. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21015" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb21-08.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-78" - ], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2021-02-11T20:15:00Z" - } -} \ No newline at end of file