mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Advisory Database Sync
This commit is contained in:
@@ -0,0 +1,122 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-gm4m-9rm8-7rxj",
|
||||
"modified": "2025-02-12T18:30:45Z",
|
||||
"published": "2022-08-20T00:00:30Z",
|
||||
"aliases": [
|
||||
"CVE-2022-35692"
|
||||
],
|
||||
"summary": "Magento Open Source has Improper Access Control vulnerability",
|
||||
"details": "Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of another user's account details. Exploitation of this issue does not require user interaction.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
"ecosystem": "Packagist",
|
||||
"name": "magento/community-edition"
|
||||
},
|
||||
"ranges": [
|
||||
{
|
||||
"type": "ECOSYSTEM",
|
||||
"events": [
|
||||
{
|
||||
"introduced": "2.4.3-p1"
|
||||
},
|
||||
{
|
||||
"fixed": "2.4.3-p3"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"package": {
|
||||
"ecosystem": "Packagist",
|
||||
"name": "magento/community-edition"
|
||||
},
|
||||
"ranges": [
|
||||
{
|
||||
"type": "ECOSYSTEM",
|
||||
"events": [
|
||||
{
|
||||
"introduced": "2.3.7-p1"
|
||||
},
|
||||
{
|
||||
"fixed": "2.3.7-p4"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"package": {
|
||||
"ecosystem": "Packagist",
|
||||
"name": "magento/project-community-edition"
|
||||
},
|
||||
"ranges": [
|
||||
{
|
||||
"type": "ECOSYSTEM",
|
||||
"events": [
|
||||
{
|
||||
"introduced": "0"
|
||||
},
|
||||
{
|
||||
"last_affected": "2.0.2"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"package": {
|
||||
"ecosystem": "Packagist",
|
||||
"name": "magento/community-edition"
|
||||
},
|
||||
"versions": [
|
||||
"2.3.7"
|
||||
]
|
||||
},
|
||||
{
|
||||
"package": {
|
||||
"ecosystem": "Packagist",
|
||||
"name": "magento/community-edition"
|
||||
},
|
||||
"versions": [
|
||||
"2.4.4"
|
||||
]
|
||||
},
|
||||
{
|
||||
"package": {
|
||||
"ecosystem": "Packagist",
|
||||
"name": "magento/community-edition"
|
||||
},
|
||||
"versions": [
|
||||
"2.4.3"
|
||||
]
|
||||
}
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35692"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://helpx.adobe.com/security/products/magento/apsb22-38.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-863"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2025-02-12T18:30:44Z",
|
||||
"nvd_published_at": "2022-08-19T23:15:00Z"
|
||||
}
|
||||
}
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cjqx-m2ff-vgj5",
|
||||
"modified": "2022-05-24T19:03:38Z",
|
||||
"modified": "2025-02-12T18:31:20Z",
|
||||
"published": "2022-05-24T19:03:38Z",
|
||||
"aliases": [
|
||||
"CVE-2021-20240"
|
||||
],
|
||||
"details": "A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code on the victim system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -18,6 +23,18 @@
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1926787"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B5H3GNVWMZTYZR3JBYCK57PF7PFMQBNP"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BGZVCTH5O7WBJLYXZ2UOKLYNIFPVR55D"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EANWYODLOJDFLMBH6WEKJJMQ5PKLEWML"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B5H3GNVWMZTYZR3JBYCK57PF7PFMQBNP"
|
||||
@@ -33,6 +50,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-191",
|
||||
"CWE-787"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -1,36 +0,0 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-gm4m-9rm8-7rxj",
|
||||
"modified": "2022-08-20T00:00:30Z",
|
||||
"published": "2022-08-20T00:00:30Z",
|
||||
"aliases": [
|
||||
"CVE-2022-35692"
|
||||
],
|
||||
"details": "Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of another user's account detials. Exploitation of this issue does not require user interaction.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35692"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://helpx.adobe.com/security/products/magento/apsb22-38.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-863"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2022-08-19T23:15:00Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-225v-7693-56j3",
|
||||
"modified": "2023-04-13T21:30:27Z",
|
||||
"modified": "2025-02-12T18:31:26Z",
|
||||
"published": "2023-04-09T21:30:14Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27720"
|
||||
|
||||
@@ -25,7 +25,9 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"cwe_ids": [
|
||||
"CWE-119"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3gqh-xgpm-cfvx",
|
||||
"modified": "2023-04-14T18:30:20Z",
|
||||
"modified": "2025-02-12T18:31:20Z",
|
||||
"published": "2023-04-05T18:30:18Z",
|
||||
"aliases": [
|
||||
"CVE-2023-29389"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-47pw-3g2g-9xj2",
|
||||
"modified": "2023-04-13T18:30:32Z",
|
||||
"modified": "2025-02-12T18:31:24Z",
|
||||
"published": "2023-04-07T15:30:39Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27808"
|
||||
@@ -19,6 +19,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27808"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/DeltriggerList"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/@0dayResearch/DeltriggerList"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4g4v-5cg8-c9g6",
|
||||
"modified": "2023-04-13T18:30:29Z",
|
||||
"modified": "2025-02-12T18:31:23Z",
|
||||
"published": "2023-04-07T00:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2023-29475"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4j6m-cxx4-9x6q",
|
||||
"modified": "2023-04-12T18:30:39Z",
|
||||
"modified": "2025-02-12T18:31:20Z",
|
||||
"published": "2023-04-05T21:30:24Z",
|
||||
"aliases": [
|
||||
"CVE-2023-1855"
|
||||
@@ -31,6 +31,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lore.kernel.org/all/20230318122758.2140868-1-linux%40roeck-us.net"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lore.kernel.org/all/20230318122758.2140868-1-linux@roeck-us.net"
|
||||
|
||||
@@ -26,6 +26,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-125",
|
||||
"CWE-89"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-64x6-jjx3-6ggh",
|
||||
"modified": "2023-04-13T18:30:32Z",
|
||||
"modified": "2025-02-12T18:31:24Z",
|
||||
"published": "2023-04-07T15:30:39Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27810"
|
||||
@@ -19,6 +19,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27810"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/ipqos_lanip_editlist"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/@0dayResearch/ipqos_lanip_editlist"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6cv9-9p4c-38fq",
|
||||
"modified": "2023-04-13T18:30:31Z",
|
||||
"modified": "2025-02-12T18:31:23Z",
|
||||
"published": "2023-04-07T15:30:39Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27801"
|
||||
@@ -19,6 +19,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27801"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/DelDNSHnList"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/@0dayResearch/DelDNSHnList"
|
||||
|
||||
@@ -25,7 +25,9 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"cwe_ids": [
|
||||
"CWE-269"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7v8p-3ffx-7rjc",
|
||||
"modified": "2023-04-13T18:30:31Z",
|
||||
"modified": "2025-02-12T18:31:23Z",
|
||||
"published": "2023-04-07T15:30:39Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27802"
|
||||
@@ -19,6 +19,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27802"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/EditvsList"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/@0dayResearch/EditvsList"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8v5j-pwr7-w5f8",
|
||||
"modified": "2023-11-25T12:30:21Z",
|
||||
"modified": "2025-02-12T18:31:21Z",
|
||||
"published": "2023-04-06T18:30:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-24534"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8v94-jg2x-f3vr",
|
||||
"modified": "2023-04-13T18:30:31Z",
|
||||
"modified": "2025-02-12T18:31:24Z",
|
||||
"published": "2023-04-07T15:30:39Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27805"
|
||||
@@ -19,6 +19,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27805"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/EditSTList"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/@0dayResearch/EditSTList"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9f7g-gqwh-jpf5",
|
||||
"modified": "2023-04-17T18:30:29Z",
|
||||
"modified": "2025-02-12T18:31:21Z",
|
||||
"published": "2023-04-06T18:30:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-24536"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-h7xj-xr99-gpjr",
|
||||
"modified": "2023-04-13T18:30:31Z",
|
||||
"modified": "2025-02-12T18:31:24Z",
|
||||
"published": "2023-04-07T15:30:39Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27806"
|
||||
@@ -19,6 +19,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27806"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/ipqos_lanip_dellist"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/@0dayResearch/ipqos_lanip_dellist"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jxf3-h258-gvf9",
|
||||
"modified": "2023-04-12T18:30:38Z",
|
||||
"modified": "2025-02-12T18:31:20Z",
|
||||
"published": "2023-04-06T06:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2023-29421"
|
||||
@@ -27,6 +27,18 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/kspalaiologos/bzip3/compare/1.2.2...1.2.3"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4JLSE25SV7K2NB6FTFT4UHJOJUHBHYHY"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NA7S7HDUAINOTCSWQZ5LIW756DYY22V2"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMLFV2FJK3CM7NJLVPZI5RUAFQZICPWW"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4JLSE25SV7K2NB6FTFT4UHJOJUHBHYHY"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m76f-5v6g-6jmr",
|
||||
"modified": "2023-04-13T18:30:30Z",
|
||||
"modified": "2025-02-12T18:31:23Z",
|
||||
"published": "2023-04-07T00:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2023-29474"
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user