diff --git a/advisories/unreviewed/2023/11/GHSA-26fg-v32r-h663/GHSA-26fg-v32r-h663.json b/advisories/github-reviewed/2023/11/GHSA-26fg-v32r-h663/GHSA-26fg-v32r-h663.json similarity index 56% rename from advisories/unreviewed/2023/11/GHSA-26fg-v32r-h663/GHSA-26fg-v32r-h663.json rename to advisories/github-reviewed/2023/11/GHSA-26fg-v32r-h663/GHSA-26fg-v32r-h663.json index 873a2716eff..ef657f9103b 100644 --- a/advisories/unreviewed/2023/11/GHSA-26fg-v32r-h663/GHSA-26fg-v32r-h663.json +++ b/advisories/github-reviewed/2023/11/GHSA-26fg-v32r-h663/GHSA-26fg-v32r-h663.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-26fg-v32r-h663", - "modified": "2023-11-09T21:30:39Z", + "modified": "2023-11-10T00:41:16Z", "published": "2023-11-09T21:30:39Z", "aliases": [ "CVE-2023-5545" ], + "summary": "Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability", "details": "H5P metadata automatically populated the author with the user's username, which could be sensitive information.", "severity": [ { @@ -14,17 +15,43 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.3.0-rc2" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5545" }, + { + "type": "WEB", + "url": "https://github.com/moodle/moodle/commit/100ac7c6467a7de2c05713a0a924984ff1593d53" + }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2243444" }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, { "type": "WEB", "url": "https://moodle.org/mod/forum/discuss.php?d=451586" @@ -39,8 +66,8 @@ "CWE-200" ], "severity": "LOW", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2023-11-10T00:41:16Z", "nvd_published_at": "2023-11-09T20:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-8mm2-m2gp-c6x2/GHSA-8mm2-m2gp-c6x2.json b/advisories/github-reviewed/2023/11/GHSA-8mm2-m2gp-c6x2/GHSA-8mm2-m2gp-c6x2.json similarity index 57% rename from advisories/unreviewed/2023/11/GHSA-8mm2-m2gp-c6x2/GHSA-8mm2-m2gp-c6x2.json rename to advisories/github-reviewed/2023/11/GHSA-8mm2-m2gp-c6x2/GHSA-8mm2-m2gp-c6x2.json index 84b04cc58b6..aee093a3e0a 100644 --- a/advisories/unreviewed/2023/11/GHSA-8mm2-m2gp-c6x2/GHSA-8mm2-m2gp-c6x2.json +++ b/advisories/github-reviewed/2023/11/GHSA-8mm2-m2gp-c6x2/GHSA-8mm2-m2gp-c6x2.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8mm2-m2gp-c6x2", - "modified": "2023-11-09T21:30:38Z", + "modified": "2023-11-10T00:40:49Z", "published": "2023-11-09T21:30:38Z", "aliases": [ "CVE-2023-5542" ], + "summary": "Moodle Improper Access Control vulnerability", "details": "Students in \"Only see own membership\" groups could see other students in the group, which should be hidden.", "severity": [ { @@ -14,17 +15,43 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.3.0-rc2" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5542" }, + { + "type": "WEB", + "url": "https://github.com/moodle/moodle/commit/b0bb97ee3b481dd85d8f1ed3612f70c9d1939014" + }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2243441" }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, { "type": "WEB", "url": "https://moodle.org/mod/forum/discuss.php?d=451583" @@ -39,8 +66,8 @@ "CWE-284" ], "severity": "LOW", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2023-11-10T00:40:49Z", "nvd_published_at": "2023-11-09T20:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9724-h8p7-r3jv/GHSA-9724-h8p7-r3jv.json b/advisories/github-reviewed/2023/11/GHSA-9724-h8p7-r3jv/GHSA-9724-h8p7-r3jv.json similarity index 57% rename from advisories/unreviewed/2023/11/GHSA-9724-h8p7-r3jv/GHSA-9724-h8p7-r3jv.json rename to advisories/github-reviewed/2023/11/GHSA-9724-h8p7-r3jv/GHSA-9724-h8p7-r3jv.json index eeb2ae71c0d..5a718cd1416 100644 --- a/advisories/unreviewed/2023/11/GHSA-9724-h8p7-r3jv/GHSA-9724-h8p7-r3jv.json +++ b/advisories/github-reviewed/2023/11/GHSA-9724-h8p7-r3jv/GHSA-9724-h8p7-r3jv.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9724-h8p7-r3jv", - "modified": "2023-11-09T21:30:38Z", + "modified": "2023-11-10T00:41:29Z", "published": "2023-11-09T21:30:38Z", "aliases": [ "CVE-2023-5546" ], + "summary": "Moodle Cross-site Scripting vulnerability", "details": "ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.", "severity": [ { @@ -14,17 +15,43 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.3.0-rc2" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5546" }, + { + "type": "WEB", + "url": "https://github.com/moodle/moodle/commit/aa8ab48521fe4a57c3ec923e6e82a5ac1202e9de" + }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2243445" }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, { "type": "WEB", "url": "https://moodle.org/mod/forum/discuss.php?d=451587" @@ -39,8 +66,8 @@ "CWE-79" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2023-11-10T00:41:29Z", "nvd_published_at": "2023-11-09T20:15:10Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9gqp-3g28-w9xc/GHSA-9gqp-3g28-w9xc.json b/advisories/github-reviewed/2023/11/GHSA-9gqp-3g28-w9xc/GHSA-9gqp-3g28-w9xc.json similarity index 52% rename from advisories/unreviewed/2023/11/GHSA-9gqp-3g28-w9xc/GHSA-9gqp-3g28-w9xc.json rename to advisories/github-reviewed/2023/11/GHSA-9gqp-3g28-w9xc/GHSA-9gqp-3g28-w9xc.json index aee3cad4152..ecb173d8aee 100644 --- a/advisories/unreviewed/2023/11/GHSA-9gqp-3g28-w9xc/GHSA-9gqp-3g28-w9xc.json +++ b/advisories/github-reviewed/2023/11/GHSA-9gqp-3g28-w9xc/GHSA-9gqp-3g28-w9xc.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9gqp-3g28-w9xc", - "modified": "2023-11-09T21:30:39Z", + "modified": "2023-11-10T00:41:42Z", "published": "2023-11-09T21:30:39Z", "aliases": [ "CVE-2023-5547" ], + "summary": "Moodle Cross-site Scripting vulnerability", "details": "The course upload preview contained an XSS risk for users uploading unsafe data.", "severity": [ { @@ -14,17 +15,47 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.3.0-rc2" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5547" }, + { + "type": "WEB", + "url": "https://github.com/moodle/moodle/commit/833e818f022cce8373922afaa0cc6c8726b6b079" + }, + { + "type": "WEB", + "url": "https://github.com/moodle/moodle/commit/ef67f43c67e00c271658e42fc2e9cbe5fc94a87e" + }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2243447" }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, { "type": "WEB", "url": "https://moodle.org/mod/forum/discuss.php?d=451588" @@ -39,8 +70,8 @@ "CWE-79" ], "severity": "LOW", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2023-11-10T00:41:42Z", "nvd_published_at": "2023-11-09T20:15:10Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-j5xf-gv89-g422/GHSA-j5xf-gv89-g422.json b/advisories/github-reviewed/2023/11/GHSA-j5xf-gv89-g422/GHSA-j5xf-gv89-g422.json similarity index 58% rename from advisories/unreviewed/2023/11/GHSA-j5xf-gv89-g422/GHSA-j5xf-gv89-g422.json rename to advisories/github-reviewed/2023/11/GHSA-j5xf-gv89-g422/GHSA-j5xf-gv89-g422.json index 608db9fc445..a12db15031d 100644 --- a/advisories/unreviewed/2023/11/GHSA-j5xf-gv89-g422/GHSA-j5xf-gv89-g422.json +++ b/advisories/github-reviewed/2023/11/GHSA-j5xf-gv89-g422/GHSA-j5xf-gv89-g422.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j5xf-gv89-g422", - "modified": "2023-11-09T21:30:39Z", + "modified": "2023-11-10T00:41:02Z", "published": "2023-11-09T21:30:39Z", "aliases": [ "CVE-2023-5544" ], + "summary": "Moodle Cross-site Scripting vulnerability", "details": "Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.", "severity": [ { @@ -14,17 +15,43 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.3.0-rc2" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5544" }, + { + "type": "WEB", + "url": "https://github.com/moodle/moodle/commit/5fec728be9df3c9fc282cd0897c73ca5cfcfea5f" + }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2243443" }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, { "type": "WEB", "url": "https://moodle.org/mod/forum/discuss.php?d=451585" @@ -39,8 +66,8 @@ "CWE-79" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2023-11-10T00:41:02Z", "nvd_published_at": "2023-11-09T20:15:09Z" } } \ No newline at end of file