From 42139ba689a56a818a6734cf5cabbccb107827a6 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 6 Nov 2024 19:53:40 +0000 Subject: [PATCH] Publish Advisories GHSA-8h4x-xvjp-vf99 GHSA-6377-hfv9-hqf6 GHSA-jjxq-ff2g-95vh --- .../GHSA-8h4x-xvjp-vf99.json | 10 ++- .../GHSA-6377-hfv9-hqf6.json | 84 +++++++++++++++++++ .../GHSA-jjxq-ff2g-95vh.json | 84 +++++++++++++++++++ 3 files changed, 175 insertions(+), 3 deletions(-) create mode 100644 advisories/github-reviewed/2024/11/GHSA-6377-hfv9-hqf6/GHSA-6377-hfv9-hqf6.json create mode 100644 advisories/github-reviewed/2024/11/GHSA-jjxq-ff2g-95vh/GHSA-jjxq-ff2g-95vh.json diff --git a/advisories/github-reviewed/2024/02/GHSA-8h4x-xvjp-vf99/GHSA-8h4x-xvjp-vf99.json b/advisories/github-reviewed/2024/02/GHSA-8h4x-xvjp-vf99/GHSA-8h4x-xvjp-vf99.json index 94f39a4d7c5..963836e6263 100644 --- a/advisories/github-reviewed/2024/02/GHSA-8h4x-xvjp-vf99/GHSA-8h4x-xvjp-vf99.json +++ b/advisories/github-reviewed/2024/02/GHSA-8h4x-xvjp-vf99/GHSA-8h4x-xvjp-vf99.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8h4x-xvjp-vf99", - "modified": "2024-02-27T19:21:29Z", + "modified": "2024-11-06T19:52:34Z", "published": "2024-02-16T23:14:45Z", "aliases": [ "CVE-2023-45860" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ @@ -166,9 +170,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-02-16T23:14:45Z", "nvd_published_at": "2024-02-16T10:15:08Z" diff --git a/advisories/github-reviewed/2024/11/GHSA-6377-hfv9-hqf6/GHSA-6377-hfv9-hqf6.json b/advisories/github-reviewed/2024/11/GHSA-6377-hfv9-hqf6/GHSA-6377-hfv9-hqf6.json new file mode 100644 index 00000000000..fcfab58f2fc --- /dev/null +++ b/advisories/github-reviewed/2024/11/GHSA-6377-hfv9-hqf6/GHSA-6377-hfv9-hqf6.json @@ -0,0 +1,84 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6377-hfv9-hqf6", + "modified": "2024-11-06T19:52:31Z", + "published": "2024-11-06T19:52:31Z", + "aliases": [ + "CVE-2024-51754" + ], + "summary": "Twig has unguarded calls to `__toString()` when nesting an object into an array", + "details": "### Description\n\nIn a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of an array or an argument list (arguments to a function or a filter for instance).\n\n### Resolution\n\nThe sandbox mode now checks the `__toString()` method call on all objects.\n\nThe patch for this issue is available [here](https://github.com/twigphp/twig/commit/407647c1036518c90b0188bb31b55f19ca84c328) for branch 3.x.\n\n### Credits\n\nWe would like to thank Jamie Schouten for reporting the issue and Fabien Potencier for providing the fix.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "twig/twig" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.11.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "twig/twig" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.12" + }, + { + "fixed": "3.14.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-6377-hfv9-hqf6" + }, + { + "type": "WEB", + "url": "https://github.com/twigphp/Twig/commit/2bb8c2460a2c519c498df9b643d5277117155a73" + }, + { + "type": "PACKAGE", + "url": "https://github.com/twigphp/Twig" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-668" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2024-11-06T19:52:31Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/11/GHSA-jjxq-ff2g-95vh/GHSA-jjxq-ff2g-95vh.json b/advisories/github-reviewed/2024/11/GHSA-jjxq-ff2g-95vh/GHSA-jjxq-ff2g-95vh.json new file mode 100644 index 00000000000..af16757d24c --- /dev/null +++ b/advisories/github-reviewed/2024/11/GHSA-jjxq-ff2g-95vh/GHSA-jjxq-ff2g-95vh.json @@ -0,0 +1,84 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjxq-ff2g-95vh", + "modified": "2024-11-06T19:52:55Z", + "published": "2024-11-06T19:52:55Z", + "aliases": [ + "CVE-2024-51755" + ], + "summary": "Twig has unguarded calls to `__isset()` and to array-accesses when the sandbox is enabled", + "details": "### Description\n\nIn a sandbox, and attacker can access attributes of Array-like objects as they were not checked by the security policy.\nThey are now checked via the property policy and the `__isset()` method is now called after the security check.\n**This is a BC break.**\n\n### Resolution\n\nThe sandbox mode now ensures access to array-like's properties is allowed.\n\nThe patch for this issue is available [here](https://github.com/twigphp/twig/commit/249615d3bfc3ce1672815a265458c0bcf8f7cc61) for branch 3.11.x.\n\n### Credits\n\nWe would like to thank Jamie Schouten for reporting the issue and Nicolas Grekas for providing the fix.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "twig/twig" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.11.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "twig/twig" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.12" + }, + { + "fixed": "3.14.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-jjxq-ff2g-95vh" + }, + { + "type": "WEB", + "url": "https://github.com/twigphp/Twig/commit/831c148e786178e5f2fde9db67266be3bf241c21" + }, + { + "type": "PACKAGE", + "url": "https://github.com/twigphp/Twig" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-668" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2024-11-06T19:52:55Z", + "nvd_published_at": null + } +} \ No newline at end of file