diff --git a/advisories/github-reviewed/2022/05/GHSA-prw8-gqwp-f7fh/GHSA-prw8-gqwp-f7fh.json b/advisories/github-reviewed/2022/05/GHSA-prw8-gqwp-f7fh/GHSA-prw8-gqwp-f7fh.json new file mode 100644 index 00000000000..5a2e1f8a56b --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-prw8-gqwp-f7fh/GHSA-prw8-gqwp-f7fh.json @@ -0,0 +1,95 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prw8-gqwp-f7fh", + "modified": "2023-07-14T23:48:05Z", + "published": "2022-05-24T16:52:27Z", + "aliases": [ + "CVE-2019-7915" + ], + "summary": "Magento 2 Community Edition DoS vulnerability", + "details": "A denial-of-service vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Under certain conditions, an unauthenticated attacker could force the Magento store's full page cache to serve a 404 page to customers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.1" + }, + { + "fixed": "2.1.18" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.2" + }, + { + "fixed": "2.2.9" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.3" + }, + { + "fixed": "2.3.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-7915" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20211206084839/https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2023-07-14T23:48:05Z", + "nvd_published_at": "2019-08-02T22:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-prw8-gqwp-f7fh/GHSA-prw8-gqwp-f7fh.json b/advisories/unreviewed/2022/05/GHSA-prw8-gqwp-f7fh/GHSA-prw8-gqwp-f7fh.json deleted file mode 100644 index 758a2a5e466..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-prw8-gqwp-f7fh/GHSA-prw8-gqwp-f7fh.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-prw8-gqwp-f7fh", - "modified": "2022-05-24T16:52:27Z", - "published": "2022-05-24T16:52:27Z", - "aliases": [ - "CVE-2019-7915" - ], - "details": "A denial-of-service vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Under certain conditions, an unauthenticated attacker could force the Magento store's full page cache to serve a 404 page to customers.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-7915" - }, - { - "type": "WEB", - "url": "https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2019-08-02T22:15:00Z" - } -} \ No newline at end of file