diff --git a/advisories/unreviewed/2024/08/GHSA-4mrc-w7jh-hx4j/GHSA-4mrc-w7jh-hx4j.json b/advisories/github-reviewed/2024/08/GHSA-4mrc-w7jh-hx4j/GHSA-4mrc-w7jh-hx4j.json similarity index 55% rename from advisories/unreviewed/2024/08/GHSA-4mrc-w7jh-hx4j/GHSA-4mrc-w7jh-hx4j.json rename to advisories/github-reviewed/2024/08/GHSA-4mrc-w7jh-hx4j/GHSA-4mrc-w7jh-hx4j.json index c78022db41d..d10959dbd1e 100644 --- a/advisories/unreviewed/2024/08/GHSA-4mrc-w7jh-hx4j/GHSA-4mrc-w7jh-hx4j.json +++ b/advisories/github-reviewed/2024/08/GHSA-4mrc-w7jh-hx4j/GHSA-4mrc-w7jh-hx4j.json @@ -1,26 +1,53 @@ { "schema_version": "1.4.0", "id": "GHSA-4mrc-w7jh-hx4j", - "modified": "2024-08-23T21:30:42Z", + "modified": "2024-08-23T22:51:35Z", "published": "2024-08-23T21:30:42Z", "aliases": [ "CVE-2024-45190" ], + "summary": "Mage AI Path Traversal vulnerability", "details": "Mage AI allows remote users with the \"Viewer\" role to leak arbitrary files from the Mage server due to a path traversal in the \"Pipeline Interaction\" request", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P" } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "mage-ai" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.9.73" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45190" }, + { + "type": "PACKAGE", + "url": "https://github.com/mage-ai/mage-ai" + }, { "type": "WEB", "url": "https://research.jfrog.com/vulnerabilities/mage-ai-pipeline-interaction-request-remote-arbitrary-file-leak-jfsa-2024-001039605" @@ -31,8 +58,8 @@ "CWE-35" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-08-23T22:51:35Z", "nvd_published_at": "2024-08-23T20:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cgxv-795x-3vqr/GHSA-cgxv-795x-3vqr.json b/advisories/github-reviewed/2024/08/GHSA-cgxv-795x-3vqr/GHSA-cgxv-795x-3vqr.json similarity index 54% rename from advisories/unreviewed/2024/08/GHSA-cgxv-795x-3vqr/GHSA-cgxv-795x-3vqr.json rename to advisories/github-reviewed/2024/08/GHSA-cgxv-795x-3vqr/GHSA-cgxv-795x-3vqr.json index a02c70952f0..eca30a8532c 100644 --- a/advisories/unreviewed/2024/08/GHSA-cgxv-795x-3vqr/GHSA-cgxv-795x-3vqr.json +++ b/advisories/github-reviewed/2024/08/GHSA-cgxv-795x-3vqr/GHSA-cgxv-795x-3vqr.json @@ -1,26 +1,53 @@ { "schema_version": "1.4.0", "id": "GHSA-cgxv-795x-3vqr", - "modified": "2024-08-23T21:30:42Z", + "modified": "2024-08-23T22:51:32Z", "published": "2024-08-23T21:30:42Z", "aliases": [ "CVE-2024-45189" ], + "summary": "Mage AI Path Traversal vulnerability", "details": "Mage AI allows remote users with the \"Viewer\" role to leak arbitrary files from the Mage server due to a path traversal in the \"Git Content\" request", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P" } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "mage-ai" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.9.73" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45189" }, + { + "type": "PACKAGE", + "url": "https://github.com/mage-ai/mage-ai" + }, { "type": "WEB", "url": "https://research.jfrog.com/vulnerabilities/mage-ai-git-content-request-remote-arbitrary-file-leak-jfsa-2024-001039604" @@ -28,11 +55,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-08-23T22:51:32Z", "nvd_published_at": "2024-08-23T20:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json b/advisories/github-reviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json similarity index 53% rename from advisories/unreviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json rename to advisories/github-reviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json index 642cadfc65a..7c51ec0e20b 100644 --- a/advisories/unreviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json +++ b/advisories/github-reviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json @@ -1,17 +1,43 @@ { "schema_version": "1.4.0", "id": "GHSA-g8h2-j9pm-4xx2", - "modified": "2024-08-23T21:30:42Z", + "modified": "2024-08-23T22:52:12Z", "published": "2024-08-23T21:30:42Z", "aliases": [ "CVE-2024-40111" ], + "summary": "Automad Cross-site Scripting vulnerability", "details": "A persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulnerability enables an attacker to inject malicious JavaScript code into the template body. The injected code is stored within the flat file CMS and is executed in the browser of any user visiting the forum.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N" + } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "automad/automad" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.0.0-alpha.4" + } + ] + } + ] + } ], "references": [ { @@ -22,6 +48,10 @@ "type": "WEB", "url": "https://drive.google.com/file/d/10BVQKYo2H1-Nx3FOGteL2xww4lbZ3xlS/view?usp=sharing" }, + { + "type": "PACKAGE", + "url": "https://github.com/marcantondahmen/automad" + }, { "type": "WEB", "url": "https://github.com/w3bn00b3r/Stored-Cross-Site-Scripting-XSS---Automad-2.0.0-alpha.4" @@ -29,11 +59,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-08-23T22:52:12Z", "nvd_published_at": "2024-08-23T21:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jg95-r9xh-xw9c/GHSA-jg95-r9xh-xw9c.json b/advisories/github-reviewed/2024/08/GHSA-jg95-r9xh-xw9c/GHSA-jg95-r9xh-xw9c.json similarity index 50% rename from advisories/unreviewed/2024/08/GHSA-jg95-r9xh-xw9c/GHSA-jg95-r9xh-xw9c.json rename to advisories/github-reviewed/2024/08/GHSA-jg95-r9xh-xw9c/GHSA-jg95-r9xh-xw9c.json index b67e16f3bc4..3ed1406117c 100644 --- a/advisories/unreviewed/2024/08/GHSA-jg95-r9xh-xw9c/GHSA-jg95-r9xh-xw9c.json +++ b/advisories/github-reviewed/2024/08/GHSA-jg95-r9xh-xw9c/GHSA-jg95-r9xh-xw9c.json @@ -1,26 +1,53 @@ { "schema_version": "1.4.0", "id": "GHSA-jg95-r9xh-xw9c", - "modified": "2024-08-23T21:30:42Z", + "modified": "2024-08-23T22:51:28Z", "published": "2024-08-23T21:30:42Z", "aliases": [ "CVE-2024-45187" ], - "details": "Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access to remotely execute arbitrary code through the Mage AI terminal server", + "summary": "Mage AI incorrectly gives privileges to users with deleted accounts", + "details": "Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access to remotely execute arbitrary code through the Mage AI terminal server.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U" } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "mage-ai" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.9.73" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45187" }, + { + "type": "PACKAGE", + "url": "https://github.com/mage-ai/mage-ai" + }, { "type": "WEB", "url": "https://research.jfrog.com/vulnerabilities/mage-ai-deleted-users-rce-jfsa-2024-001039602" @@ -30,9 +57,9 @@ "cwe_ids": [ "CWE-266" ], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-08-23T22:51:28Z", "nvd_published_at": "2024-08-23T19:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v9wr-8wrm-h6p7/GHSA-v9wr-8wrm-h6p7.json b/advisories/github-reviewed/2024/08/GHSA-v9wr-8wrm-h6p7/GHSA-v9wr-8wrm-h6p7.json similarity index 54% rename from advisories/unreviewed/2024/08/GHSA-v9wr-8wrm-h6p7/GHSA-v9wr-8wrm-h6p7.json rename to advisories/github-reviewed/2024/08/GHSA-v9wr-8wrm-h6p7/GHSA-v9wr-8wrm-h6p7.json index 7d05536f212..42d0faa5651 100644 --- a/advisories/unreviewed/2024/08/GHSA-v9wr-8wrm-h6p7/GHSA-v9wr-8wrm-h6p7.json +++ b/advisories/github-reviewed/2024/08/GHSA-v9wr-8wrm-h6p7/GHSA-v9wr-8wrm-h6p7.json @@ -1,26 +1,53 @@ { "schema_version": "1.4.0", "id": "GHSA-v9wr-8wrm-h6p7", - "modified": "2024-08-23T21:30:42Z", + "modified": "2024-08-23T22:51:30Z", "published": "2024-08-23T21:30:42Z", "aliases": [ "CVE-2024-45188" ], + "summary": "Mage AI Path Traversal vulnerability", "details": "Mage AI allows remote users with the \"Viewer\" role to leak arbitrary files from the Mage server due to a path traversal in the \"File Content\" request", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P" } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "mage-ai" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.9.73" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45188" }, + { + "type": "PACKAGE", + "url": "https://github.com/mage-ai/mage-ai" + }, { "type": "WEB", "url": "https://research.jfrog.com/vulnerabilities/mage-ai-file-content-request-remote-arbitrary-file-leak-jfsa-2024-001039603" @@ -28,11 +55,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-08-23T22:51:30Z", "nvd_published_at": "2024-08-23T20:15:07Z" } } \ No newline at end of file