diff --git a/advisories/github-reviewed/2022/05/GHSA-474f-cmx5-gm69/GHSA-474f-cmx5-gm69.json b/advisories/github-reviewed/2022/05/GHSA-474f-cmx5-gm69/GHSA-474f-cmx5-gm69.json new file mode 100644 index 00000000000..bff1d490848 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-474f-cmx5-gm69/GHSA-474f-cmx5-gm69.json @@ -0,0 +1,107 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-474f-cmx5-gm69", + "modified": "2025-05-28T20:08:55Z", + "published": "2022-05-24T19:09:46Z", + "aliases": [ + "CVE-2021-33324" + ], + "summary": "Liferay Portal and Liferay DXP Don't Check Permissions of Pages", + "details": "The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 5, does not properly check permission of pages, which allows remote authenticated users without view permission of a page to view the page via a site's page administration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.portal.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.1.0" + }, + { + "last_affected": "7.3.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "7.1.10.fp20" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.2.0" + }, + { + "fixed": "7.2.10.fp5" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33324" + }, + { + "type": "PACKAGE", + "url": "https://github.com/liferay/liferay-portal" + }, + { + "type": "WEB", + "url": "https://issues.liferay.com/browse/LPE-17001" + }, + { + "type": "WEB", + "url": "https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120747063" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20220828222955/https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120747063" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-05-28T20:08:55Z", + "nvd_published_at": "2021-08-03T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-mj8w-h522-jwm8/GHSA-mj8w-h522-jwm8.json b/advisories/github-reviewed/2022/05/GHSA-mj8w-h522-jwm8/GHSA-mj8w-h522-jwm8.json new file mode 100644 index 00000000000..f61a698c327 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-mj8w-h522-jwm8/GHSA-mj8w-h522-jwm8.json @@ -0,0 +1,122 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj8w-h522-jwm8", + "modified": "2025-05-28T20:09:15Z", + "published": "2022-05-24T19:09:41Z", + "aliases": [ + "CVE-2021-33331" + ], + "summary": "Liferay Portal and Liferay DXP Allows Arbitrary Redirect of Users to External URLs", + "details": "Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19 and 7.2 before fix pack 8, allows remote attackers to redirect users to arbitrary external URLs via the 'redirect' parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.portal.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.0.0" + }, + { + "last_affected": "7.3.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.0.10.fp0" + }, + { + "fixed": "7.0.10.fp94" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.1.0" + }, + { + "fixed": "7.1.10.fp19" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.2.0" + }, + { + "fixed": "7.2.10.fp8" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33331" + }, + { + "type": "PACKAGE", + "url": "https://github.com/liferay/liferay-portal" + }, + { + "type": "WEB", + "url": "https://issues.liferay.com/browse/LPE-17022" + }, + { + "type": "WEB", + "url": "https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120747627" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-05-28T20:09:15Z", + "nvd_published_at": "2021-08-03T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-xx2h-2hf5-v7vv/GHSA-xx2h-2hf5-v7vv.json b/advisories/github-reviewed/2022/05/GHSA-xx2h-2hf5-v7vv/GHSA-xx2h-2hf5-v7vv.json new file mode 100644 index 00000000000..7ee7b27cfb0 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-xx2h-2hf5-v7vv/GHSA-xx2h-2hf5-v7vv.json @@ -0,0 +1,149 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx2h-2hf5-v7vv", + "modified": "2025-05-28T20:10:38Z", + "published": "2022-05-24T19:02:39Z", + "aliases": [ + "CVE-2021-29043" + ], + "summary": "Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password", + "details": "The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the S3 store's proxy password, which allows attackers to steal the proxy password via man-in-the-middle attacks or shoulder surfing.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.portal.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.0.0" + }, + { + "fixed": "7.3.6" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 7.3.5" + } + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "7.0.10.fp97" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.1.0" + }, + { + "fixed": "7.1.10.fp21" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.2.0" + }, + { + "fixed": "7.2.10.fp10" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.3.0" + }, + { + "fixed": "7.3.10.fp1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-29043" + }, + { + "type": "PACKAGE", + "url": "https://github.com/liferay/liferay-portal" + }, + { + "type": "WEB", + "url": "https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120743515" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20210517183617/https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120743515" + }, + { + "type": "WEB", + "url": "http://liferay.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200", + "CWE-522" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-05-28T20:10:38Z", + "nvd_published_at": "2021-05-17T11:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/05/GHSA-424x-cxvh-wq9p/GHSA-424x-cxvh-wq9p.json b/advisories/github-reviewed/2025/05/GHSA-424x-cxvh-wq9p/GHSA-424x-cxvh-wq9p.json index b622be14597..5ef24d5aedb 100644 --- a/advisories/github-reviewed/2025/05/GHSA-424x-cxvh-wq9p/GHSA-424x-cxvh-wq9p.json +++ b/advisories/github-reviewed/2025/05/GHSA-424x-cxvh-wq9p/GHSA-424x-cxvh-wq9p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-424x-cxvh-wq9p", - "modified": "2025-05-28T17:38:46Z", + "modified": "2025-05-28T20:08:12Z", "published": "2025-05-28T17:38:46Z", "aliases": [ "CVE-2024-47057" @@ -78,6 +78,10 @@ "type": "WEB", "url": "https://github.com/mautic/mautic/security/advisories/GHSA-424x-cxvh-wq9p" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47057" + }, { "type": "PACKAGE", "url": "https://github.com/mautic/mautic" @@ -85,11 +89,12 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-204" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-05-28T17:38:46Z", - "nvd_published_at": null + "nvd_published_at": "2025-05-28T18:15:25Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2025/05/GHSA-cqx4-9vqf-q3m8/GHSA-cqx4-9vqf-q3m8.json b/advisories/github-reviewed/2025/05/GHSA-cqx4-9vqf-q3m8/GHSA-cqx4-9vqf-q3m8.json index dfd24f75969..41b46561295 100644 --- a/advisories/github-reviewed/2025/05/GHSA-cqx4-9vqf-q3m8/GHSA-cqx4-9vqf-q3m8.json +++ b/advisories/github-reviewed/2025/05/GHSA-cqx4-9vqf-q3m8/GHSA-cqx4-9vqf-q3m8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cqx4-9vqf-q3m8", - "modified": "2025-05-28T17:38:14Z", + "modified": "2025-05-28T20:08:01Z", "published": "2025-05-28T17:38:13Z", "aliases": [ "CVE-2025-5257" @@ -78,6 +78,10 @@ "type": "WEB", "url": "https://github.com/mautic/mautic/security/advisories/GHSA-cqx4-9vqf-q3m8" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5257" + }, { "type": "PACKAGE", "url": "https://github.com/mautic/mautic" @@ -85,11 +89,12 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-284" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-05-28T17:38:13Z", - "nvd_published_at": null + "nvd_published_at": "2025-05-28T17:15:25Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2025/05/GHSA-h2wg-v8wg-jhxh/GHSA-h2wg-v8wg-jhxh.json b/advisories/github-reviewed/2025/05/GHSA-h2wg-v8wg-jhxh/GHSA-h2wg-v8wg-jhxh.json index c9e2e5af9b2..0a893cbee01 100644 --- a/advisories/github-reviewed/2025/05/GHSA-h2wg-v8wg-jhxh/GHSA-h2wg-v8wg-jhxh.json +++ b/advisories/github-reviewed/2025/05/GHSA-h2wg-v8wg-jhxh/GHSA-h2wg-v8wg-jhxh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h2wg-v8wg-jhxh", - "modified": "2025-05-28T17:38:38Z", + "modified": "2025-05-28T20:07:50Z", "published": "2025-05-28T17:38:38Z", "aliases": [ "CVE-2024-47056" @@ -78,6 +78,10 @@ "type": "WEB", "url": "https://github.com/mautic/mautic/security/advisories/GHSA-h2wg-v8wg-jhxh" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47056" + }, { "type": "PACKAGE", "url": "https://github.com/mautic/mautic" @@ -85,11 +89,12 @@ ], "database_specific": { "cwe_ids": [ + "CWE-312", "CWE-526" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-05-28T17:38:38Z", - "nvd_published_at": null + "nvd_published_at": "2025-05-28T17:15:23Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2025/05/GHSA-vph5-ghq3-q782/GHSA-vph5-ghq3-q782.json b/advisories/github-reviewed/2025/05/GHSA-vph5-ghq3-q782/GHSA-vph5-ghq3-q782.json index 4385f1b2827..8bd7d68ef00 100644 --- a/advisories/github-reviewed/2025/05/GHSA-vph5-ghq3-q782/GHSA-vph5-ghq3-q782.json +++ b/advisories/github-reviewed/2025/05/GHSA-vph5-ghq3-q782/GHSA-vph5-ghq3-q782.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vph5-ghq3-q782", - "modified": "2025-05-28T17:38:58Z", + "modified": "2025-05-28T20:08:20Z", "published": "2025-05-28T17:38:58Z", "aliases": [ "CVE-2024-47055" @@ -59,6 +59,10 @@ "type": "WEB", "url": "https://github.com/mautic/mautic/security/advisories/GHSA-vph5-ghq3-q782" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47055" + }, { "type": "PACKAGE", "url": "https://github.com/mautic/mautic" @@ -66,11 +70,12 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-05-28T17:38:58Z", - "nvd_published_at": null + "nvd_published_at": "2025-05-28T18:15:24Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2025/05/GHSA-wxr5-93ph-8wr9/GHSA-wxr5-93ph-8wr9.json b/advisories/github-reviewed/2025/05/GHSA-wxr5-93ph-8wr9/GHSA-wxr5-93ph-8wr9.json index baa366c6143..7934cb08590 100644 --- a/advisories/github-reviewed/2025/05/GHSA-wxr5-93ph-8wr9/GHSA-wxr5-93ph-8wr9.json +++ b/advisories/github-reviewed/2025/05/GHSA-wxr5-93ph-8wr9/GHSA-wxr5-93ph-8wr9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wxr5-93ph-8wr9", - "modified": "2025-05-28T17:37:18Z", + "modified": "2025-05-28T20:07:35Z", "published": "2025-05-28T15:34:34Z", "aliases": [ "CVE-2025-48734" @@ -73,6 +73,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/s0hb3jkfj5f3ryx6c57zqtfohb0of1g9" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/28/6" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-474f-cmx5-gm69/GHSA-474f-cmx5-gm69.json b/advisories/unreviewed/2022/05/GHSA-474f-cmx5-gm69/GHSA-474f-cmx5-gm69.json deleted file mode 100644 index b9bbf013f14..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-474f-cmx5-gm69/GHSA-474f-cmx5-gm69.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-474f-cmx5-gm69", - "modified": "2022-05-24T19:09:46Z", - "published": "2022-05-24T19:09:46Z", - "aliases": [ - "CVE-2021-33324" - ], - "details": "The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 5, does not properly check permission of pages, which allows remote authenticated users without view permission of a page to view the page via a site's page administration.", - "severity": [], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33324" - }, - { - "type": "WEB", - "url": "https://issues.liferay.com/browse/LPE-17001" - }, - { - "type": "WEB", - "url": "https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120747063" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-276" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2021-08-03T19:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-mj8w-h522-jwm8/GHSA-mj8w-h522-jwm8.json b/advisories/unreviewed/2022/05/GHSA-mj8w-h522-jwm8/GHSA-mj8w-h522-jwm8.json deleted file mode 100644 index 5b6cf97ef3a..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-mj8w-h522-jwm8/GHSA-mj8w-h522-jwm8.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-mj8w-h522-jwm8", - "modified": "2022-05-24T19:09:41Z", - "published": "2022-05-24T19:09:41Z", - "aliases": [ - "CVE-2021-33331" - ], - "details": "Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19 and 7.2 before fix pack 8, allows remote attackers to redirect users to arbitrary external URLs via the 'redirect' parameter.", - "severity": [], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33331" - }, - { - "type": "WEB", - "url": "https://issues.liferay.com/browse/LPE-17022" - }, - { - "type": "WEB", - "url": "https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120747627" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-601" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2021-08-03T21:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-xx2h-2hf5-v7vv/GHSA-xx2h-2hf5-v7vv.json b/advisories/unreviewed/2022/05/GHSA-xx2h-2hf5-v7vv/GHSA-xx2h-2hf5-v7vv.json deleted file mode 100644 index 54d57caf655..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-xx2h-2hf5-v7vv/GHSA-xx2h-2hf5-v7vv.json +++ /dev/null @@ -1,40 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-xx2h-2hf5-v7vv", - "modified": "2022-06-29T00:00:50Z", - "published": "2022-05-24T19:02:39Z", - "aliases": [ - "CVE-2021-29043" - ], - "details": "The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the S3 store's proxy password, which allows attackers to steal the proxy password via man-in-the-middle attacks or shoulder surfing.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-29043" - }, - { - "type": "WEB", - "url": "https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120743515" - }, - { - "type": "WEB", - "url": "http://liferay.com" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-200" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2021-05-17T11:15:00Z" - } -} \ No newline at end of file