Publish Advisories

GHSA-3p4x-grpm-xw58
GHSA-665w-mwrr-77q3
GHSA-96qm-hwhp-2rm8
This commit is contained in:
advisory-database[bot]
2024-06-10 20:24:32 +00:00
parent 9587cd4524
commit 3c89740d88
3 changed files with 12 additions and 4 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3p4x-grpm-xw58",
"modified": "2024-06-06T19:13:50Z",
"modified": "2024-06-10T20:22:12Z",
"published": "2024-06-06T12:30:36Z",
"aliases": [
"CVE-2024-5657"
@@ -59,6 +59,10 @@
{
"type": "WEB",
"url": "https://plugins.craftcms.com/two-factor-authentication?craft4"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/06/06/1"
}
],
"database_specific": {
@@ -1,10 +1,10 @@
{
"schema_version": "1.4.0",
"id": "GHSA-665w-mwrr-77q3",
"modified": "2024-06-05T13:29:10Z",
"modified": "2024-06-10T20:22:45Z",
"published": "2024-06-05T13:29:10Z",
"aliases": [
"CVE-2024-37169"
],
"summary": "Arbitrary file read via Playwright's screenshot feature exploiting file wrapper",
"details": "### Impact\n\nAll users of url-to-png. Please see https://github.com/jasonraimondi/url-to-png/issues/47\n\n### Patches\n\n[v2.0.3](https://github.com/jasonraimondi/url-to-png/releases/tag/v2.0.3) requires input url to be of protocol `http` or `https` \n\n### Workarounds\n\nRequires upgrade.\n\n### References\n\n- https://github.com/jasonraimondi/url-to-png/issues/47\n- https://github.com/user-attachments/files/15536336/Arbitrary.File.Read.via.Playwright.s.Screenshot.Feature.Exploiting.File.Wrapper.pdf\n",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-96qm-hwhp-2rm8",
"modified": "2024-06-06T19:12:06Z",
"modified": "2024-06-10T20:21:44Z",
"published": "2024-06-06T12:30:36Z",
"aliases": [
"CVE-2024-5658"
@@ -59,6 +59,10 @@
{
"type": "WEB",
"url": "https://plugins.craftcms.com/two-factor-authentication?craft4"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/06/06/2"
}
],
"database_specific": {