From 1ed94bbaa7f32491f4ec985acb9bdb95b911e0df Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 28 Jan 2025 19:16:19 +0000 Subject: [PATCH] Publish Advisories GHSA-8m8m-98c9-vw7q GHSA-hj78-p4h7-m5fv GHSA-hp5j-2585-qx6g GHSA-q53r-9hh9-w277 GHSA-8m8m-98c9-vw7q --- .../GHSA-8m8m-98c9-vw7q.json | 76 +++++++++++++++++ .../GHSA-hj78-p4h7-m5fv.json | 58 +++++++++++++ .../GHSA-hp5j-2585-qx6g.json | 33 +++++++- .../GHSA-q53r-9hh9-w277.json | 81 +++++++++++++++++++ .../GHSA-8m8m-98c9-vw7q.json | 56 ------------- 5 files changed, 244 insertions(+), 60 deletions(-) create mode 100644 advisories/github-reviewed/2025/01/GHSA-8m8m-98c9-vw7q/GHSA-8m8m-98c9-vw7q.json create mode 100644 advisories/github-reviewed/2025/01/GHSA-hj78-p4h7-m5fv/GHSA-hj78-p4h7-m5fv.json rename advisories/{unreviewed => github-reviewed}/2025/01/GHSA-hp5j-2585-qx6g/GHSA-hp5j-2585-qx6g.json (63%) create mode 100644 advisories/github-reviewed/2025/01/GHSA-q53r-9hh9-w277/GHSA-q53r-9hh9-w277.json delete mode 100644 advisories/unreviewed/2025/01/GHSA-8m8m-98c9-vw7q/GHSA-8m8m-98c9-vw7q.json diff --git a/advisories/github-reviewed/2025/01/GHSA-8m8m-98c9-vw7q/GHSA-8m8m-98c9-vw7q.json b/advisories/github-reviewed/2025/01/GHSA-8m8m-98c9-vw7q/GHSA-8m8m-98c9-vw7q.json new file mode 100644 index 00000000000..1c55249087e --- /dev/null +++ b/advisories/github-reviewed/2025/01/GHSA-8m8m-98c9-vw7q/GHSA-8m8m-98c9-vw7q.json @@ -0,0 +1,76 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m8m-98c9-vw7q", + "modified": "2025-01-28T19:14:30Z", + "published": "2025-01-28T15:31:57Z", + "withdrawn": "2025-01-28T19:14:30Z", + "aliases": [], + "summary": "Duplicate Advisory: pimcore/customer-data-framework vulnerable to SQL Injection: Hibernate", + "details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-q53r-9hh9-w277. This link is maintained to preserve external references.\n\n## Original Description\nA vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affected by this issue is some unknown functionality of the file /admin/customermanagementframework/customers/list. The manipulation of the argument filterDefinition/filter leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "pimcore/customer-data-framework" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.2.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pimcore/pimcore/security/advisories/GHSA-q53r-9hh9-w277" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11956" + }, + { + "type": "WEB", + "url": "https://github.com/pimcore/customer-data-framework/releases/tag/v4.2.1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293906" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293906" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.451863" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-01-28T19:14:30Z", + "nvd_published_at": "2025-01-28T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-hj78-p4h7-m5fv/GHSA-hj78-p4h7-m5fv.json b/advisories/github-reviewed/2025/01/GHSA-hj78-p4h7-m5fv/GHSA-hj78-p4h7-m5fv.json new file mode 100644 index 00000000000..51f0d1b5b4e --- /dev/null +++ b/advisories/github-reviewed/2025/01/GHSA-hj78-p4h7-m5fv/GHSA-hj78-p4h7-m5fv.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj78-p4h7-m5fv", + "modified": "2025-01-28T19:15:44Z", + "published": "2025-01-28T19:15:44Z", + "aliases": [ + "CVE-2025-24856" + ], + "summary": "TYPO3-EXT-SA-2025-001: Account Takeover in extension \"OpenID Connect Authentication\" (oidc)", + "details": "## Problem Description\nA vulnerability in the account linking logic of the extension allows a pre-hijacking attack leading to Account Takeover. The attack can only be exploited if the following requirements are met:\n\n- An attacker can anticipate the email address of the user.\n- An attacker can register a public frontend user account using that email address before the user's first OIDC login.\n- The IDP returns the field email containing the email address of the user\n\n## Solution\nAn updated versions 4.0.0 is available from the TYPO3 extension manager, packagist and at \nhttps://extensions.typo3.org/extension/download/oidc/4.0.0/zip\n\nUsers of the extension are advised to update the extension as soon as possible.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "causal/oidc" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.0.0" + }, + { + "fixed": "4.0.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/causal/oidc/CVE-2025-24856.yaml" + }, + { + "type": "WEB", + "url": "https://typo3.org/security/advisory/typo3-ext-sa-2025-001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288", + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-01-28T19:15:44Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hp5j-2585-qx6g/GHSA-hp5j-2585-qx6g.json b/advisories/github-reviewed/2025/01/GHSA-hp5j-2585-qx6g/GHSA-hp5j-2585-qx6g.json similarity index 63% rename from advisories/unreviewed/2025/01/GHSA-hp5j-2585-qx6g/GHSA-hp5j-2585-qx6g.json rename to advisories/github-reviewed/2025/01/GHSA-hp5j-2585-qx6g/GHSA-hp5j-2585-qx6g.json index 9b308d5be7c..69dd69dc453 100644 --- a/advisories/unreviewed/2025/01/GHSA-hp5j-2585-qx6g/GHSA-hp5j-2585-qx6g.json +++ b/advisories/github-reviewed/2025/01/GHSA-hp5j-2585-qx6g/GHSA-hp5j-2585-qx6g.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-hp5j-2585-qx6g", - "modified": "2025-01-28T12:31:07Z", + "modified": "2025-01-28T19:15:28Z", "published": "2025-01-28T12:31:07Z", "aliases": [ "CVE-2025-0750" ], + "summary": "CRI-O Path Traversal vulnerability", "details": "A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system directories.", "severity": [ { @@ -13,7 +14,27 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" } ], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/cri-o/cri-o" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "1.33.0" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", @@ -26,6 +47,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339405" + }, + { + "type": "PACKAGE", + "url": "https://github.com/cri-o/cri-o" } ], "database_specific": { @@ -33,8 +58,8 @@ "CWE-22" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-01-28T19:15:28Z", "nvd_published_at": "2025-01-28T10:15:09Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-q53r-9hh9-w277/GHSA-q53r-9hh9-w277.json b/advisories/github-reviewed/2025/01/GHSA-q53r-9hh9-w277/GHSA-q53r-9hh9-w277.json new file mode 100644 index 00000000000..c554b573973 --- /dev/null +++ b/advisories/github-reviewed/2025/01/GHSA-q53r-9hh9-w277/GHSA-q53r-9hh9-w277.json @@ -0,0 +1,81 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q53r-9hh9-w277", + "modified": "2025-01-28T19:14:50Z", + "published": "2025-01-28T19:14:50Z", + "aliases": [ + "CVE-2024-11956" + ], + "summary": "pimcore/customer-data-framework vulnerable to SQL Injection", + "details": "An SQL injection vulnerability allows any authenticated user to execute arbitrary SQL commands on the server. This can lead to unauthorized access to sensitive data, data modification, or even complete control over the server.\n\nDetails\nThe vulnerability is found in the URL parameters of the following endpoint:\n\n`GET /admin/customermanagementframework/customers/list?add-new-customer=1&apply-segment-selection=Apply&filterDefinition[allowedRoleIds][]=1&filterDefinition[allowedUserIds][]=2&filterDefinition[id]=0&filterDefinition[name]=RDFYjolf&filterDefinition[readOnly]=on&filterDefinition[shortcutAvailable]=on&filter[active]=1&filter[email]=testing%40example.com&filter[firstname]=RDFYjolf&filter[id]=1&filter[lastname]=RDFYjolf&filter[operator-customer]=AND&filter[operator-segments]=%40%40dz1Uu&filter[search]=the&filter[segments][832][]=847&filter[segments][833][]=835&filter[segments][874][]=876&filter[showSegments][]=832 HTTP/1.1`\n\nThe parameters filterDefinition and filter are vulnerable to SQL injection. When a specially crafted input is provided, it results in an SQL error, indicating that the input is being directly used in an SQL query without proper sanitization.\n\nPoC\nTo reproduce the vulnerability, follow these steps:\n\nOpen a web browser or a tool like curl or Postman.\nAuthenticate with valid user credentials.\nNavigate to the following URL with the vulnerable parameters:\n```\nhttps://demo.pimcore.fun/admin/customermanagementframework/customers/list?add-new-customer=1&apply-segment-selection=Apply&filterDefinition[allowedRoleIds][]=1&filterDefinition[allowedUserIds][]=2&filterDefinition[id]=0&filterDefinition[name]=RDFYjolf&filterDefinition[readOnly]=on&filterDefinition[shortcutAvailable]=on&filter[active]=1&filter[email]=testing%40example.com&filter[firstname]=RDFYjolf&filter[id]=1&filter[lastname]=RDFYjolf&filter[operator-customer]=AND&filter[operator-segments]=%40%40dz1Uu&filter[search]=the&filter[segments][832][]=847&filter[segments][833][]=835&filter[segments][874][]=876&filter[showSegments][]=832\nObserve the error message indicating an SQL error:\nError while building customer list: An exception occurred while executing a query: SQLSTATE[42000]: Syntax error or access violation: 1064 You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near '@_0 ON `fltr_seg_832_0_@_0`.fieldname IN ('manualSegments','calculatedSegment...' at line 1\n```\nImpact\nThis is an SQL injection vulnerability. It impacts any authenticated user who can access the affected endpoint. An attacker can exploit this vulnerability to execute arbitrary SQL commands, potentially leading to data breaches, data loss, or full server compromise.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "pimcore/customer-management-framework-bundle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.2.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pimcore/pimcore/security/advisories/GHSA-q53r-9hh9-w277" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11956" + }, + { + "type": "WEB", + "url": "https://github.com/pimcore/customer-data-framework/releases/tag/v4.2.1" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pimcore/pimcore" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293906" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293906" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.451863" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-564" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-01-28T19:14:50Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8m8m-98c9-vw7q/GHSA-8m8m-98c9-vw7q.json b/advisories/unreviewed/2025/01/GHSA-8m8m-98c9-vw7q/GHSA-8m8m-98c9-vw7q.json deleted file mode 100644 index 221fa8df6f9..00000000000 --- a/advisories/unreviewed/2025/01/GHSA-8m8m-98c9-vw7q/GHSA-8m8m-98c9-vw7q.json +++ /dev/null @@ -1,56 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-8m8m-98c9-vw7q", - "modified": "2025-01-28T15:31:57Z", - "published": "2025-01-28T15:31:57Z", - "aliases": [ - "CVE-2024-11956" - ], - "details": "A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affected by this issue is some unknown functionality of the file /admin/customermanagementframework/customers/list. The manipulation of the argument filterDefinition/filter leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" - }, - { - "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" - } - ], - "affected": [], - "references": [ - { - "type": "WEB", - "url": "https://github.com/pimcore/pimcore/security/advisories/GHSA-q53r-9hh9-w277" - }, - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11956" - }, - { - "type": "WEB", - "url": "https://github.com/pimcore/customer-data-framework/releases/tag/v4.2.1" - }, - { - "type": "WEB", - "url": "https://vuldb.com/?ctiid.293906" - }, - { - "type": "WEB", - "url": "https://vuldb.com/?id.293906" - }, - { - "type": "WEB", - "url": "https://vuldb.com/?submit.451863" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-74" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-01-28T14:15:29Z" - } -} \ No newline at end of file