From 2c5d96d00c9bc8e4ad6aa908ecc49ab08fdc414c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 17 Dec 2024 22:31:05 +0000 Subject: [PATCH] Publish Advisories GHSA-4hxr-28mv-q729 GHSA-5mpw-4546-2wcr GHSA-4hxr-28mv-q729 --- .../GHSA-4hxr-28mv-q729.json | 80 +++++++++++++++++++ .../GHSA-5mpw-4546-2wcr.json | 35 ++++++-- .../GHSA-4hxr-28mv-q729.json | 36 --------- 3 files changed, 110 insertions(+), 41 deletions(-) create mode 100644 advisories/github-reviewed/2024/12/GHSA-4hxr-28mv-q729/GHSA-4hxr-28mv-q729.json rename advisories/{unreviewed => github-reviewed}/2024/12/GHSA-5mpw-4546-2wcr/GHSA-5mpw-4546-2wcr.json (57%) delete mode 100644 advisories/unreviewed/2024/12/GHSA-4hxr-28mv-q729/GHSA-4hxr-28mv-q729.json diff --git a/advisories/github-reviewed/2024/12/GHSA-4hxr-28mv-q729/GHSA-4hxr-28mv-q729.json b/advisories/github-reviewed/2024/12/GHSA-4hxr-28mv-q729/GHSA-4hxr-28mv-q729.json new file mode 100644 index 00000000000..2598fef5b8b --- /dev/null +++ b/advisories/github-reviewed/2024/12/GHSA-4hxr-28mv-q729/GHSA-4hxr-28mv-q729.json @@ -0,0 +1,80 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hxr-28mv-q729", + "modified": "2024-12-17T22:29:33Z", + "published": "2024-12-17T21:30:34Z", + "aliases": [ + "CVE-2024-11993" + ], + "summary": "Liferay Portal and Liferay DXP vulnerable to Criss-site Scripting", + "details": "Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.1.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38, 7.3 GA through update 36, 7.2 GA through fix pack 20 and 7.1 GA through fix pack 28 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.portal.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.1.0" + }, + { + "fixed": "7.4.3.39" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.1" + }, + { + "fixed": "7.4.13.u39" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11993" + }, + { + "type": "PACKAGE", + "url": "https://github.com/liferay/liferay-portal" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-11993" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-12-17T22:29:33Z", + "nvd_published_at": "2024-12-17T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5mpw-4546-2wcr/GHSA-5mpw-4546-2wcr.json b/advisories/github-reviewed/2024/12/GHSA-5mpw-4546-2wcr/GHSA-5mpw-4546-2wcr.json similarity index 57% rename from advisories/unreviewed/2024/12/GHSA-5mpw-4546-2wcr/GHSA-5mpw-4546-2wcr.json rename to advisories/github-reviewed/2024/12/GHSA-5mpw-4546-2wcr/GHSA-5mpw-4546-2wcr.json index 5f28497a891..52c65c88fde 100644 --- a/advisories/unreviewed/2024/12/GHSA-5mpw-4546-2wcr/GHSA-5mpw-4546-2wcr.json +++ b/advisories/github-reviewed/2024/12/GHSA-5mpw-4546-2wcr/GHSA-5mpw-4546-2wcr.json @@ -1,19 +1,40 @@ { "schema_version": "1.4.0", "id": "GHSA-5mpw-4546-2wcr", - "modified": "2024-12-17T21:30:34Z", + "modified": "2024-12-17T22:30:17Z", "published": "2024-12-17T21:30:34Z", "aliases": [ "CVE-2024-12539" ], + "summary": "Elasticsearch Incorrect Authorization vulnerability", "details": "An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.", "severity": [ { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.elasticsearch:elasticsearch" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.16.0" + }, + { + "fixed": "8.16.2" + } + ] + } + ] } ], - "affected": [], "references": [ { "type": "ADVISORY", @@ -22,6 +43,10 @@ { "type": "WEB", "url": "https://discuss.elastic.co/t/elasticsearch-8-16-2-8-17-0-security-update/372091" + }, + { + "type": "PACKAGE", + "url": "https://github.com/elastic/elasticsearch" } ], "database_specific": { @@ -29,8 +54,8 @@ "CWE-863" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-12-17T22:30:17Z", "nvd_published_at": "2024-12-17T21:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4hxr-28mv-q729/GHSA-4hxr-28mv-q729.json b/advisories/unreviewed/2024/12/GHSA-4hxr-28mv-q729/GHSA-4hxr-28mv-q729.json deleted file mode 100644 index 3fcadd85c74..00000000000 --- a/advisories/unreviewed/2024/12/GHSA-4hxr-28mv-q729/GHSA-4hxr-28mv-q729.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-4hxr-28mv-q729", - "modified": "2024-12-17T21:30:34Z", - "published": "2024-12-17T21:30:34Z", - "aliases": [ - "CVE-2024-11993" - ], - "details": "Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.1.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38, 7.3 GA through update 36, 7.2 GA through fix pack 20 and 7.1 GA through fix pack 28 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field", - "severity": [ - { - "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11993" - }, - { - "type": "WEB", - "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-11993" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-12-17T21:15:07Z" - } -} \ No newline at end of file