diff --git a/advisories/github-reviewed/2025/01/GHSA-69cg-w8vm-h229/GHSA-69cg-w8vm-h229.json b/advisories/github-reviewed/2025/01/GHSA-69cg-w8vm-h229/GHSA-69cg-w8vm-h229.json index a00aaa18ddc..9d399eabb41 100644 --- a/advisories/github-reviewed/2025/01/GHSA-69cg-w8vm-h229/GHSA-69cg-w8vm-h229.json +++ b/advisories/github-reviewed/2025/01/GHSA-69cg-w8vm-h229/GHSA-69cg-w8vm-h229.json @@ -1,11 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-69cg-w8vm-h229", - "modified": "2025-01-21T21:24:20Z", + "modified": "2025-02-19T17:59:39Z", "published": "2025-01-21T21:24:20Z", - "aliases": [], + "aliases": [ + "CVE-2024-10761" + ], "summary": "XSS/HTML Injection Vulnerability in Umbraco Preview Badge", - "details": "### Impact\n\nAuthenticated users are able to exploit an XSS vulnerability when viewing previewed content.\n\n### Patches\n\nWill be patched in 10.8.8, 13.5.3, 14.3.2 and 15.1.2.\n\n### Workarounds\n\nNone available.\n", + "details": "### Impact\n\nAuthenticated users are able to exploit an XSS vulnerability when viewing previewed content.\n\n### Patches\n\nWill be patched in 10.8.8, 13.5.3, 14.3.2 and 15.1.2.\n\n### Workarounds\n\nNone available.", "severity": [ { "type": "CVSS_V3", @@ -13,25 +15,6 @@ } ], "affected": [ - { - "package": { - "ecosystem": "NuGet", - "name": "Umbraco.Cms" - }, - "ranges": [ - { - "type": "ECOSYSTEM", - "events": [ - { - "introduced": "10.8.7" - }, - { - "fixed": "10.8.8" - } - ] - } - ] - }, { "package": { "ecosystem": "NuGet", @@ -88,6 +71,101 @@ ] } ] + }, + { + "package": { + "ecosystem": "NuGet", + "name": "Umbraco.Cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.8.7" + }, + { + "fixed": "10.8.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "NuGet", + "name": "Umbraco.Cms.Web.Common" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "11.0.0" + }, + { + "fixed": "13.5.3" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "NuGet", + "name": "Umbraco.Cms.Web.Common" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "14.0.0" + }, + { + "fixed": "14.3.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "NuGet", + "name": "Umbraco.Cms.Web.Common" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.0.0" + }, + { + "fixed": "15.1.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "NuGet", + "name": "Umbraco.Cms.Web.Common" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.8.7" + }, + { + "fixed": "10.8.8" + } + ] + } + ] } ], "references": [ @@ -95,9 +173,29 @@ "type": "WEB", "url": "https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-69cg-w8vm-h229" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10761" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1YoZgdlS3QT7Xu005j9RO-FFUT8RbB0Da/view?usp=sharing" + }, { "type": "PACKAGE", "url": "https://github.com/umbraco/Umbraco-CMS" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282930" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282930" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.427091" } ], "database_specific": {