From 31581a29c8ff902a71973649ddece86ab9e21f9c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 14 Jul 2023 23:49:24 +0000 Subject: [PATCH] Publish Advisories GHSA-prw8-gqwp-f7fh GHSA-prw8-gqwp-f7fh --- .../GHSA-prw8-gqwp-f7fh.json | 95 +++++++++++++++++++ .../GHSA-prw8-gqwp-f7fh.json | 35 ------- 2 files changed, 95 insertions(+), 35 deletions(-) create mode 100644 advisories/github-reviewed/2022/05/GHSA-prw8-gqwp-f7fh/GHSA-prw8-gqwp-f7fh.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-prw8-gqwp-f7fh/GHSA-prw8-gqwp-f7fh.json diff --git a/advisories/github-reviewed/2022/05/GHSA-prw8-gqwp-f7fh/GHSA-prw8-gqwp-f7fh.json b/advisories/github-reviewed/2022/05/GHSA-prw8-gqwp-f7fh/GHSA-prw8-gqwp-f7fh.json new file mode 100644 index 00000000000..5a2e1f8a56b --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-prw8-gqwp-f7fh/GHSA-prw8-gqwp-f7fh.json @@ -0,0 +1,95 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prw8-gqwp-f7fh", + "modified": "2023-07-14T23:48:05Z", + "published": "2022-05-24T16:52:27Z", + "aliases": [ + "CVE-2019-7915" + ], + "summary": "Magento 2 Community Edition DoS vulnerability", + "details": "A denial-of-service vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Under certain conditions, an unauthenticated attacker could force the Magento store's full page cache to serve a 404 page to customers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.1" + }, + { + "fixed": "2.1.18" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.2" + }, + { + "fixed": "2.2.9" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.3" + }, + { + "fixed": "2.3.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-7915" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20211206084839/https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2023-07-14T23:48:05Z", + "nvd_published_at": "2019-08-02T22:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-prw8-gqwp-f7fh/GHSA-prw8-gqwp-f7fh.json b/advisories/unreviewed/2022/05/GHSA-prw8-gqwp-f7fh/GHSA-prw8-gqwp-f7fh.json deleted file mode 100644 index 758a2a5e466..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-prw8-gqwp-f7fh/GHSA-prw8-gqwp-f7fh.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-prw8-gqwp-f7fh", - "modified": "2022-05-24T16:52:27Z", - "published": "2022-05-24T16:52:27Z", - "aliases": [ - "CVE-2019-7915" - ], - "details": "A denial-of-service vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Under certain conditions, an unauthenticated attacker could force the Magento store's full page cache to serve a 404 page to customers.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-7915" - }, - { - "type": "WEB", - "url": "https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2019-08-02T22:15:00Z" - } -} \ No newline at end of file