Publish Advisories

GHSA-xhqw-4hcq-fcvr
GHSA-f963-4cq8-2gw7
GHSA-r6ph-5fp2-3w2v
GHSA-wcg9-pgqv-xm5v
GHSA-r6ph-5fp2-3w2v
This commit is contained in:
advisory-database[bot]
2024-08-19 21:50:13 +00:00
parent 3ca3b61600
commit 399108870c
5 changed files with 355 additions and 43 deletions
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xhqw-4hcq-fcvr",
"modified": "2024-07-31T09:30:49Z",
"modified": "2024-08-19T21:49:26Z",
"published": "2024-07-31T09:30:49Z",
"aliases": [
"CVE-2024-7300"
],
"summary": "Bolt CMS Cross-site Scripting vulnerability",
"details": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file /bolt/editcontent/showcases of the component Showcase Creation Handler. The manipulation of the argument textarea leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273168. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life.",
"severity": [
{
@@ -18,13 +19,35 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "bolt/bolt"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.7.1"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7300"
},
{
"type": "PACKAGE",
"url": "https://github.com/bolt/bolt"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.273168"
@@ -43,8 +66,8 @@
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-08-19T21:49:26Z",
"nvd_published_at": "2024-07-31T07:15:02Z"
}
}
@@ -0,0 +1,113 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f963-4cq8-2gw7",
"modified": "2024-08-19T21:49:15Z",
"published": "2024-08-19T21:49:15Z",
"aliases": [
"CVE-2024-43401"
],
"summary": "In XWiki Platform, payloads stored in content is executed when a user with script/programming right edit them",
"details": "### Impact\n\nA user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor.\nThe user with elevated rights is not warned beforehand that they are going to edit possibly dangerous content.\nThe payload is executed at edit time.\n\n### Patches\n\nThis vulnerability has been patched in XWiki 15.10RC1.\n\n### Workarounds\n\nNo workaround. It is advised to upgrade to XWiki 15.10+.\n\n### References\n\n* https://jira.xwiki.org/browse/XWIKI-20331\n* https://jira.xwiki.org/browse/XWIKI-21311\n* https://jira.xwiki.org/browse/XWIKI-21481\n* https://jira.xwiki.org/browse/XWIKI-21482\n* https://jira.xwiki.org/browse/XWIKI-21483\n* https://jira.xwiki.org/browse/XWIKI-21484\n* https://jira.xwiki.org/browse/XWIKI-21485\n* https://jira.xwiki.org/browse/XWIKI-21486\n* https://jira.xwiki.org/browse/XWIKI-21487\n* https://jira.xwiki.org/browse/XWIKI-21488\n* https://jira.xwiki.org/browse/XWIKI-21489\n* https://jira.xwiki.org/browse/XWIKI-21490\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)\n* Email us at [Security Mailing List](mailto:security@xwiki.org)\n\n### Attribution\n\nThis vulnerability has been reported on Intigriti by @floerer",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.xwiki.platform:xwiki-platform-web-templates"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "15.10-rc-1"
}
]
}
]
}
],
"references": [
{
"type": "WEB",
"url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-f963-4cq8-2gw7"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43401"
},
{
"type": "PACKAGE",
"url": "https://github.com/xwiki/xwiki-platform"
},
{
"type": "WEB",
"url": "https://jira.xwiki.org/browse/XWIKI-20331"
},
{
"type": "WEB",
"url": "https://jira.xwiki.org/browse/XWIKI-21311"
},
{
"type": "WEB",
"url": "https://jira.xwiki.org/browse/XWIKI-21481"
},
{
"type": "WEB",
"url": "https://jira.xwiki.org/browse/XWIKI-21482"
},
{
"type": "WEB",
"url": "https://jira.xwiki.org/browse/XWIKI-21483"
},
{
"type": "WEB",
"url": "https://jira.xwiki.org/browse/XWIKI-21484"
},
{
"type": "WEB",
"url": "https://jira.xwiki.org/browse/XWIKI-21485"
},
{
"type": "WEB",
"url": "https://jira.xwiki.org/browse/XWIKI-21486"
},
{
"type": "WEB",
"url": "https://jira.xwiki.org/browse/XWIKI-21487"
},
{
"type": "WEB",
"url": "https://jira.xwiki.org/browse/XWIKI-21488"
},
{
"type": "WEB",
"url": "https://jira.xwiki.org/browse/XWIKI-21489"
},
{
"type": "WEB",
"url": "https://jira.xwiki.org/browse/XWIKI-21490"
}
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2024-08-19T21:49:15Z",
"nvd_published_at": "2024-08-19T17:15:09Z"
}
}
@@ -0,0 +1,82 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r6ph-5fp2-3w2v",
"modified": "2024-08-19T21:48:56Z",
"published": "2024-08-19T03:30:48Z",
"aliases": [
"CVE-2024-44076"
],
"summary": "Microcks's POST /api/import and POST /api/export endpoints allow non-administrator access",
"details": "In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "io.github.microcks:microcks-app"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.10.0"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44076"
},
{
"type": "WEB",
"url": "https://github.com/microcks/microcks/issues/1212"
},
{
"type": "WEB",
"url": "https://github.com/microcks/microcks/commit/4bb98d76f050710e42f5978877fe70e2f6edabf0"
},
{
"type": "WEB",
"url": "https://github.com/microcks/microcks/commit/a47d105eb45dac5a0712d6e6bf12b3a4347e5e68"
},
{
"type": "PACKAGE",
"url": "https://github.com/microcks/microcks"
},
{
"type": "WEB",
"url": "https://github.com/microcks/microcks/compare/1.9.1-fix-1...1.10.0"
},
{
"type": "WEB",
"url": "https://github.com/microcks/microcks/releases/tag/1.10.0"
}
],
"database_specific": {
"cwe_ids": [
"CWE-269",
"CWE-863"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-08-19T21:48:56Z",
"nvd_published_at": "2024-08-19T03:15:03Z"
}
}
@@ -0,0 +1,133 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wcg9-pgqv-xm5v",
"modified": "2024-08-19T21:49:07Z",
"published": "2024-08-19T21:49:07Z",
"aliases": [
"CVE-2024-43400"
],
"summary": "XWiki Platform allows XSS through XClass name in string properties",
"details": "### Impact\nIs it possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript.\nThis requires social engineer to trick a user to follow the URL.\n\n#### Reproduction steps\n\n1. As a user without script or programming right, create a (non-terminal) document named `\" + alert(1) + \"` (the quotes need to be part of the name).\n1. Edit the class.\n1. Add a string property named `\"test\"`.\n1. Edit using the object editor and add an object of the created class\n1. Get an admin to open `<xwiki-server>/xwiki/bin/view/%22%20%2B%20alert(1)%20%2B%20%22/?viewer=display&type=object&property=%22%20%2B%20alert(1)%20%2B%20%22.WebHome.test&mode=edit` where `<xwiki-server>` is the URL of your XWiki installation.\n\n### Patches\nThis has been patched in XWiki 14.10.21, 15.5.5, 15.10.6 and 16.0.0.\n\n### Workarounds\n\nWe're not aware of any workaround except upgrading.\n\n### References\n- https://jira.xwiki.org/browse/XWIKI-21810\n- https://github.com/xwiki/xwiki-platform/commit/27eca8423fc1ad177518077a733076821268509c\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.xwiki.platform:xwiki-platform-oldcore"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.1.2"
},
{
"fixed": "14.10.21"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.xwiki.platform:xwiki-platform-oldcore"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "15.0-rc-1"
},
{
"fixed": "15.5.5"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.xwiki.platform:xwiki-platform-oldcore"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "15.6-rc-1"
},
{
"fixed": "15.10.6"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.xwiki.platform:xwiki-platform-oldcore"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "16.0.0-rc-1"
},
{
"fixed": "16.0.0"
}
]
}
],
"versions": [
"16.0.0-rc-1"
]
}
],
"references": [
{
"type": "WEB",
"url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-wcg9-pgqv-xm5v"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43400"
},
{
"type": "WEB",
"url": "https://github.com/xwiki/xwiki-platform/commit/27eca8423fc1ad177518077a733076821268509c"
},
{
"type": "PACKAGE",
"url": "https://github.com/xwiki/xwiki-platform"
},
{
"type": "WEB",
"url": "https://jira.xwiki.org/browse/XWIKI-21810"
}
],
"database_specific": {
"cwe_ids": [
"CWE-96"
],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2024-08-19T21:49:07Z",
"nvd_published_at": "2024-08-19T17:15:09Z"
}
}
@@ -1,39 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r6ph-5fp2-3w2v",
"modified": "2024-08-19T03:30:48Z",
"published": "2024-08-19T03:30:48Z",
"aliases": [
"CVE-2024-44076"
],
"details": "In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44076"
},
{
"type": "WEB",
"url": "https://github.com/microcks/microcks/issues/1212"
},
{
"type": "WEB",
"url": "https://github.com/microcks/microcks/compare/1.9.1-fix-1...1.10.0"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-19T03:15:03Z"
}
}