From 399108870c62d6dbad7a02abf63bd462beddd6ad Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 19 Aug 2024 21:50:13 +0000 Subject: [PATCH] Publish Advisories GHSA-xhqw-4hcq-fcvr GHSA-f963-4cq8-2gw7 GHSA-r6ph-5fp2-3w2v GHSA-wcg9-pgqv-xm5v GHSA-r6ph-5fp2-3w2v --- .../GHSA-xhqw-4hcq-fcvr.json | 31 +++- .../GHSA-f963-4cq8-2gw7.json | 113 +++++++++++++++ .../GHSA-r6ph-5fp2-3w2v.json | 82 +++++++++++ .../GHSA-wcg9-pgqv-xm5v.json | 133 ++++++++++++++++++ .../GHSA-r6ph-5fp2-3w2v.json | 39 ----- 5 files changed, 355 insertions(+), 43 deletions(-) rename advisories/{unreviewed => github-reviewed}/2024/07/GHSA-xhqw-4hcq-fcvr/GHSA-xhqw-4hcq-fcvr.json (73%) create mode 100644 advisories/github-reviewed/2024/08/GHSA-f963-4cq8-2gw7/GHSA-f963-4cq8-2gw7.json create mode 100644 advisories/github-reviewed/2024/08/GHSA-r6ph-5fp2-3w2v/GHSA-r6ph-5fp2-3w2v.json create mode 100644 advisories/github-reviewed/2024/08/GHSA-wcg9-pgqv-xm5v/GHSA-wcg9-pgqv-xm5v.json delete mode 100644 advisories/unreviewed/2024/08/GHSA-r6ph-5fp2-3w2v/GHSA-r6ph-5fp2-3w2v.json diff --git a/advisories/unreviewed/2024/07/GHSA-xhqw-4hcq-fcvr/GHSA-xhqw-4hcq-fcvr.json b/advisories/github-reviewed/2024/07/GHSA-xhqw-4hcq-fcvr/GHSA-xhqw-4hcq-fcvr.json similarity index 73% rename from advisories/unreviewed/2024/07/GHSA-xhqw-4hcq-fcvr/GHSA-xhqw-4hcq-fcvr.json rename to advisories/github-reviewed/2024/07/GHSA-xhqw-4hcq-fcvr/GHSA-xhqw-4hcq-fcvr.json index 80a1173190c..d8831d85edb 100644 --- a/advisories/unreviewed/2024/07/GHSA-xhqw-4hcq-fcvr/GHSA-xhqw-4hcq-fcvr.json +++ b/advisories/github-reviewed/2024/07/GHSA-xhqw-4hcq-fcvr/GHSA-xhqw-4hcq-fcvr.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xhqw-4hcq-fcvr", - "modified": "2024-07-31T09:30:49Z", + "modified": "2024-08-19T21:49:26Z", "published": "2024-07-31T09:30:49Z", "aliases": [ "CVE-2024-7300" ], + "summary": "Bolt CMS Cross-site Scripting vulnerability", "details": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file /bolt/editcontent/showcases of the component Showcase Creation Handler. The manipulation of the argument textarea leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273168. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life.", "severity": [ { @@ -18,13 +19,35 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "bolt/bolt" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "3.7.1" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7300" }, + { + "type": "PACKAGE", + "url": "https://github.com/bolt/bolt" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.273168" @@ -43,8 +66,8 @@ "CWE-79" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-08-19T21:49:26Z", "nvd_published_at": "2024-07-31T07:15:02Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/08/GHSA-f963-4cq8-2gw7/GHSA-f963-4cq8-2gw7.json b/advisories/github-reviewed/2024/08/GHSA-f963-4cq8-2gw7/GHSA-f963-4cq8-2gw7.json new file mode 100644 index 00000000000..4399032744e --- /dev/null +++ b/advisories/github-reviewed/2024/08/GHSA-f963-4cq8-2gw7/GHSA-f963-4cq8-2gw7.json @@ -0,0 +1,113 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f963-4cq8-2gw7", + "modified": "2024-08-19T21:49:15Z", + "published": "2024-08-19T21:49:15Z", + "aliases": [ + "CVE-2024-43401" + ], + "summary": "In XWiki Platform, payloads stored in content is executed when a user with script/programming right edit them", + "details": "### Impact\n\nA user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor.\nThe user with elevated rights is not warned beforehand that they are going to edit possibly dangerous content.\nThe payload is executed at edit time.\n\n### Patches\n\nThis vulnerability has been patched in XWiki 15.10RC1.\n\n### Workarounds\n\nNo workaround. It is advised to upgrade to XWiki 15.10+.\n\n### References\n\n* https://jira.xwiki.org/browse/XWIKI-20331\n* https://jira.xwiki.org/browse/XWIKI-21311\n* https://jira.xwiki.org/browse/XWIKI-21481\n* https://jira.xwiki.org/browse/XWIKI-21482\n* https://jira.xwiki.org/browse/XWIKI-21483\n* https://jira.xwiki.org/browse/XWIKI-21484\n* https://jira.xwiki.org/browse/XWIKI-21485\n* https://jira.xwiki.org/browse/XWIKI-21486\n* https://jira.xwiki.org/browse/XWIKI-21487\n* https://jira.xwiki.org/browse/XWIKI-21488\n* https://jira.xwiki.org/browse/XWIKI-21489\n* https://jira.xwiki.org/browse/XWIKI-21490\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)\n* Email us at [Security Mailing List](mailto:security@xwiki.org)\n\n### Attribution\n\nThis vulnerability has been reported on Intigriti by @floerer", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-web-templates" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "15.10-rc-1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-f963-4cq8-2gw7" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43401" + }, + { + "type": "PACKAGE", + "url": "https://github.com/xwiki/xwiki-platform" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-20331" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21311" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21481" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21482" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21483" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21484" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21485" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21486" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21487" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21488" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21489" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21490" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-08-19T21:49:15Z", + "nvd_published_at": "2024-08-19T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/08/GHSA-r6ph-5fp2-3w2v/GHSA-r6ph-5fp2-3w2v.json b/advisories/github-reviewed/2024/08/GHSA-r6ph-5fp2-3w2v/GHSA-r6ph-5fp2-3w2v.json new file mode 100644 index 00000000000..d01652b6e4a --- /dev/null +++ b/advisories/github-reviewed/2024/08/GHSA-r6ph-5fp2-3w2v/GHSA-r6ph-5fp2-3w2v.json @@ -0,0 +1,82 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6ph-5fp2-3w2v", + "modified": "2024-08-19T21:48:56Z", + "published": "2024-08-19T03:30:48Z", + "aliases": [ + "CVE-2024-44076" + ], + "summary": "Microcks's POST /api/import and POST /api/export endpoints allow non-administrator access", + "details": "In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "io.github.microcks:microcks-app" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.10.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44076" + }, + { + "type": "WEB", + "url": "https://github.com/microcks/microcks/issues/1212" + }, + { + "type": "WEB", + "url": "https://github.com/microcks/microcks/commit/4bb98d76f050710e42f5978877fe70e2f6edabf0" + }, + { + "type": "WEB", + "url": "https://github.com/microcks/microcks/commit/a47d105eb45dac5a0712d6e6bf12b3a4347e5e68" + }, + { + "type": "PACKAGE", + "url": "https://github.com/microcks/microcks" + }, + { + "type": "WEB", + "url": "https://github.com/microcks/microcks/compare/1.9.1-fix-1...1.10.0" + }, + { + "type": "WEB", + "url": "https://github.com/microcks/microcks/releases/tag/1.10.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269", + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-08-19T21:48:56Z", + "nvd_published_at": "2024-08-19T03:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/08/GHSA-wcg9-pgqv-xm5v/GHSA-wcg9-pgqv-xm5v.json b/advisories/github-reviewed/2024/08/GHSA-wcg9-pgqv-xm5v/GHSA-wcg9-pgqv-xm5v.json new file mode 100644 index 00000000000..636725ac587 --- /dev/null +++ b/advisories/github-reviewed/2024/08/GHSA-wcg9-pgqv-xm5v/GHSA-wcg9-pgqv-xm5v.json @@ -0,0 +1,133 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcg9-pgqv-xm5v", + "modified": "2024-08-19T21:49:07Z", + "published": "2024-08-19T21:49:07Z", + "aliases": [ + "CVE-2024-43400" + ], + "summary": "XWiki Platform allows XSS through XClass name in string properties", + "details": "### Impact\nIs it possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript.\nThis requires social engineer to trick a user to follow the URL.\n\n#### Reproduction steps\n\n1. As a user without script or programming right, create a (non-terminal) document named `\" + alert(1) + \"` (the quotes need to be part of the name).\n1. Edit the class.\n1. Add a string property named `\"test\"`.\n1. Edit using the object editor and add an object of the created class\n1. Get an admin to open `/xwiki/bin/view/%22%20%2B%20alert(1)%20%2B%20%22/?viewer=display&type=object&property=%22%20%2B%20alert(1)%20%2B%20%22.WebHome.test&mode=edit` where `` is the URL of your XWiki installation.\n\n### Patches\nThis has been patched in XWiki 14.10.21, 15.5.5, 15.10.6 and 16.0.0.\n\n### Workarounds\n\nWe're not aware of any workaround except upgrading.\n\n### References\n- https://jira.xwiki.org/browse/XWIKI-21810\n- https://github.com/xwiki/xwiki-platform/commit/27eca8423fc1ad177518077a733076821268509c\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-oldcore" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.1.2" + }, + { + "fixed": "14.10.21" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-oldcore" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.0-rc-1" + }, + { + "fixed": "15.5.5" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-oldcore" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.6-rc-1" + }, + { + "fixed": "15.10.6" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.xwiki.platform:xwiki-platform-oldcore" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "16.0.0-rc-1" + }, + { + "fixed": "16.0.0" + } + ] + } + ], + "versions": [ + "16.0.0-rc-1" + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-wcg9-pgqv-xm5v" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43400" + }, + { + "type": "WEB", + "url": "https://github.com/xwiki/xwiki-platform/commit/27eca8423fc1ad177518077a733076821268509c" + }, + { + "type": "PACKAGE", + "url": "https://github.com/xwiki/xwiki-platform" + }, + { + "type": "WEB", + "url": "https://jira.xwiki.org/browse/XWIKI-21810" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-96" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-08-19T21:49:07Z", + "nvd_published_at": "2024-08-19T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r6ph-5fp2-3w2v/GHSA-r6ph-5fp2-3w2v.json b/advisories/unreviewed/2024/08/GHSA-r6ph-5fp2-3w2v/GHSA-r6ph-5fp2-3w2v.json deleted file mode 100644 index 0573bcde4e0..00000000000 --- a/advisories/unreviewed/2024/08/GHSA-r6ph-5fp2-3w2v/GHSA-r6ph-5fp2-3w2v.json +++ /dev/null @@ -1,39 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-r6ph-5fp2-3w2v", - "modified": "2024-08-19T03:30:48Z", - "published": "2024-08-19T03:30:48Z", - "aliases": [ - "CVE-2024-44076" - ], - "details": "In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44076" - }, - { - "type": "WEB", - "url": "https://github.com/microcks/microcks/issues/1212" - }, - { - "type": "WEB", - "url": "https://github.com/microcks/microcks/compare/1.9.1-fix-1...1.10.0" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-08-19T03:15:03Z" - } -} \ No newline at end of file