From 338cd2e2775d74c74e51457497bf074e09ed163c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 11 Jan 2024 16:03:18 +0000 Subject: [PATCH] Publish Advisories GHSA-55gv-hfg3-hwjq GHSA-8wm7-h2qh-ff4c GHSA-55gv-hfg3-hwjq GHSA-8wm7-h2qh-ff4c --- .../GHSA-55gv-hfg3-hwjq.json | 99 +++++++++++++++++++ .../GHSA-8wm7-h2qh-ff4c.json | 99 +++++++++++++++++++ .../GHSA-55gv-hfg3-hwjq.json | 35 ------- .../GHSA-8wm7-h2qh-ff4c.json | 35 ------- 4 files changed, 198 insertions(+), 70 deletions(-) create mode 100644 advisories/github-reviewed/2022/05/GHSA-55gv-hfg3-hwjq/GHSA-55gv-hfg3-hwjq.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-8wm7-h2qh-ff4c/GHSA-8wm7-h2qh-ff4c.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-55gv-hfg3-hwjq/GHSA-55gv-hfg3-hwjq.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-8wm7-h2qh-ff4c/GHSA-8wm7-h2qh-ff4c.json diff --git a/advisories/github-reviewed/2022/05/GHSA-55gv-hfg3-hwjq/GHSA-55gv-hfg3-hwjq.json b/advisories/github-reviewed/2022/05/GHSA-55gv-hfg3-hwjq/GHSA-55gv-hfg3-hwjq.json new file mode 100644 index 00000000000..ca8012a9251 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-55gv-hfg3-hwjq/GHSA-55gv-hfg3-hwjq.json @@ -0,0 +1,99 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55gv-hfg3-hwjq", + "modified": "2024-01-11T16:02:12Z", + "published": "2022-05-24T17:21:49Z", + "aliases": [ + "CVE-2020-9585" + ], + "summary": "Magento Defense-in-depth security mitigation vulnerability", + "details": "Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.2.11" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.3.0" + }, + { + "fixed": "2.3.4-p2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.9.4.5" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9585" + }, + { + "type": "PACKAGE", + "url": "https://github.com/magento/magento2" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb20-22.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-01-11T16:02:12Z", + "nvd_published_at": "2020-06-26T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-8wm7-h2qh-ff4c/GHSA-8wm7-h2qh-ff4c.json b/advisories/github-reviewed/2022/05/GHSA-8wm7-h2qh-ff4c/GHSA-8wm7-h2qh-ff4c.json new file mode 100644 index 00000000000..28d697dcf82 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-8wm7-h2qh-ff4c/GHSA-8wm7-h2qh-ff4c.json @@ -0,0 +1,99 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wm7-h2qh-ff4c", + "modified": "2024-01-11T16:00:40Z", + "published": "2022-05-24T17:21:49Z", + "aliases": [ + "CVE-2020-9587" + ], + "summary": "Magento authorization bypass vulnerability", + "details": "Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an authorization bypass vulnerability. Successful exploitation could lead to potentially unauthorized product discounts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.2.11" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.3.0" + }, + { + "fixed": "2.3.4-p2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.9.4.5" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9587" + }, + { + "type": "PACKAGE", + "url": "https://github.com/magento/magento2" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb20-22.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-01-11T16:00:40Z", + "nvd_published_at": "2020-06-26T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-55gv-hfg3-hwjq/GHSA-55gv-hfg3-hwjq.json b/advisories/unreviewed/2022/05/GHSA-55gv-hfg3-hwjq/GHSA-55gv-hfg3-hwjq.json deleted file mode 100644 index 2cf67e72254..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-55gv-hfg3-hwjq/GHSA-55gv-hfg3-hwjq.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-55gv-hfg3-hwjq", - "modified": "2022-05-24T17:21:49Z", - "published": "2022-05-24T17:21:49Z", - "aliases": [ - "CVE-2020-9585" - ], - "details": "Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9585" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb20-22.html" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2020-06-26T21:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-8wm7-h2qh-ff4c/GHSA-8wm7-h2qh-ff4c.json b/advisories/unreviewed/2022/05/GHSA-8wm7-h2qh-ff4c/GHSA-8wm7-h2qh-ff4c.json deleted file mode 100644 index d0842441a13..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-8wm7-h2qh-ff4c/GHSA-8wm7-h2qh-ff4c.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-8wm7-h2qh-ff4c", - "modified": "2022-05-24T17:21:49Z", - "published": "2022-05-24T17:21:49Z", - "aliases": [ - "CVE-2020-9587" - ], - "details": "Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an authorization bypass vulnerability. Successful exploitation could lead to potentially unauthorized product discounts.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9587" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb20-22.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-863" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2020-06-26T21:15:00Z" - } -} \ No newline at end of file