diff --git a/advisories/github-reviewed/2024/12/GHSA-4hxr-28mv-q729/GHSA-4hxr-28mv-q729.json b/advisories/github-reviewed/2024/12/GHSA-4hxr-28mv-q729/GHSA-4hxr-28mv-q729.json new file mode 100644 index 00000000000..2598fef5b8b --- /dev/null +++ b/advisories/github-reviewed/2024/12/GHSA-4hxr-28mv-q729/GHSA-4hxr-28mv-q729.json @@ -0,0 +1,80 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hxr-28mv-q729", + "modified": "2024-12-17T22:29:33Z", + "published": "2024-12-17T21:30:34Z", + "aliases": [ + "CVE-2024-11993" + ], + "summary": "Liferay Portal and Liferay DXP vulnerable to Criss-site Scripting", + "details": "Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.1.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38, 7.3 GA through update 36, 7.2 GA through fix pack 20 and 7.1 GA through fix pack 28 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.portal.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.1.0" + }, + { + "fixed": "7.4.3.39" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.1" + }, + { + "fixed": "7.4.13.u39" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11993" + }, + { + "type": "PACKAGE", + "url": "https://github.com/liferay/liferay-portal" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-11993" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-12-17T22:29:33Z", + "nvd_published_at": "2024-12-17T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5mpw-4546-2wcr/GHSA-5mpw-4546-2wcr.json b/advisories/github-reviewed/2024/12/GHSA-5mpw-4546-2wcr/GHSA-5mpw-4546-2wcr.json similarity index 57% rename from advisories/unreviewed/2024/12/GHSA-5mpw-4546-2wcr/GHSA-5mpw-4546-2wcr.json rename to advisories/github-reviewed/2024/12/GHSA-5mpw-4546-2wcr/GHSA-5mpw-4546-2wcr.json index 5f28497a891..52c65c88fde 100644 --- a/advisories/unreviewed/2024/12/GHSA-5mpw-4546-2wcr/GHSA-5mpw-4546-2wcr.json +++ b/advisories/github-reviewed/2024/12/GHSA-5mpw-4546-2wcr/GHSA-5mpw-4546-2wcr.json @@ -1,19 +1,40 @@ { "schema_version": "1.4.0", "id": "GHSA-5mpw-4546-2wcr", - "modified": "2024-12-17T21:30:34Z", + "modified": "2024-12-17T22:30:17Z", "published": "2024-12-17T21:30:34Z", "aliases": [ "CVE-2024-12539" ], + "summary": "Elasticsearch Incorrect Authorization vulnerability", "details": "An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.", "severity": [ { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.elasticsearch:elasticsearch" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.16.0" + }, + { + "fixed": "8.16.2" + } + ] + } + ] } ], - "affected": [], "references": [ { "type": "ADVISORY", @@ -22,6 +43,10 @@ { "type": "WEB", "url": "https://discuss.elastic.co/t/elasticsearch-8-16-2-8-17-0-security-update/372091" + }, + { + "type": "PACKAGE", + "url": "https://github.com/elastic/elasticsearch" } ], "database_specific": { @@ -29,8 +54,8 @@ "CWE-863" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-12-17T22:30:17Z", "nvd_published_at": "2024-12-17T21:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4hxr-28mv-q729/GHSA-4hxr-28mv-q729.json b/advisories/unreviewed/2024/12/GHSA-4hxr-28mv-q729/GHSA-4hxr-28mv-q729.json deleted file mode 100644 index 3fcadd85c74..00000000000 --- a/advisories/unreviewed/2024/12/GHSA-4hxr-28mv-q729/GHSA-4hxr-28mv-q729.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-4hxr-28mv-q729", - "modified": "2024-12-17T21:30:34Z", - "published": "2024-12-17T21:30:34Z", - "aliases": [ - "CVE-2024-11993" - ], - "details": "Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.1.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38, 7.3 GA through update 36, 7.2 GA through fix pack 20 and 7.1 GA through fix pack 28 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field", - "severity": [ - { - "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11993" - }, - { - "type": "WEB", - "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-11993" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-12-17T21:15:07Z" - } -} \ No newline at end of file