diff --git a/advisories/github-reviewed/2022/05/GHSA-55gv-hfg3-hwjq/GHSA-55gv-hfg3-hwjq.json b/advisories/github-reviewed/2022/05/GHSA-55gv-hfg3-hwjq/GHSA-55gv-hfg3-hwjq.json new file mode 100644 index 00000000000..ca8012a9251 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-55gv-hfg3-hwjq/GHSA-55gv-hfg3-hwjq.json @@ -0,0 +1,99 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55gv-hfg3-hwjq", + "modified": "2024-01-11T16:02:12Z", + "published": "2022-05-24T17:21:49Z", + "aliases": [ + "CVE-2020-9585" + ], + "summary": "Magento Defense-in-depth security mitigation vulnerability", + "details": "Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.2.11" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.3.0" + }, + { + "fixed": "2.3.4-p2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.9.4.5" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9585" + }, + { + "type": "PACKAGE", + "url": "https://github.com/magento/magento2" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb20-22.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-01-11T16:02:12Z", + "nvd_published_at": "2020-06-26T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-8wm7-h2qh-ff4c/GHSA-8wm7-h2qh-ff4c.json b/advisories/github-reviewed/2022/05/GHSA-8wm7-h2qh-ff4c/GHSA-8wm7-h2qh-ff4c.json new file mode 100644 index 00000000000..28d697dcf82 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-8wm7-h2qh-ff4c/GHSA-8wm7-h2qh-ff4c.json @@ -0,0 +1,99 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wm7-h2qh-ff4c", + "modified": "2024-01-11T16:00:40Z", + "published": "2022-05-24T17:21:49Z", + "aliases": [ + "CVE-2020-9587" + ], + "summary": "Magento authorization bypass vulnerability", + "details": "Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an authorization bypass vulnerability. Successful exploitation could lead to potentially unauthorized product discounts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.2.11" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.3.0" + }, + { + "fixed": "2.3.4-p2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.9.4.5" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9587" + }, + { + "type": "PACKAGE", + "url": "https://github.com/magento/magento2" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb20-22.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-01-11T16:00:40Z", + "nvd_published_at": "2020-06-26T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-55gv-hfg3-hwjq/GHSA-55gv-hfg3-hwjq.json b/advisories/unreviewed/2022/05/GHSA-55gv-hfg3-hwjq/GHSA-55gv-hfg3-hwjq.json deleted file mode 100644 index 2cf67e72254..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-55gv-hfg3-hwjq/GHSA-55gv-hfg3-hwjq.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-55gv-hfg3-hwjq", - "modified": "2022-05-24T17:21:49Z", - "published": "2022-05-24T17:21:49Z", - "aliases": [ - "CVE-2020-9585" - ], - "details": "Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9585" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb20-22.html" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2020-06-26T21:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-8wm7-h2qh-ff4c/GHSA-8wm7-h2qh-ff4c.json b/advisories/unreviewed/2022/05/GHSA-8wm7-h2qh-ff4c/GHSA-8wm7-h2qh-ff4c.json deleted file mode 100644 index d0842441a13..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-8wm7-h2qh-ff4c/GHSA-8wm7-h2qh-ff4c.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-8wm7-h2qh-ff4c", - "modified": "2022-05-24T17:21:49Z", - "published": "2022-05-24T17:21:49Z", - "aliases": [ - "CVE-2020-9587" - ], - "details": "Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an authorization bypass vulnerability. Successful exploitation could lead to potentially unauthorized product discounts.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9587" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb20-22.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-863" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2020-06-26T21:15:00Z" - } -} \ No newline at end of file