From 6c0976a093df9f0d09d8c1e478052838a392dde7 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 27 Jun 2023 18:39:21 +0000 Subject: [PATCH] Publish Advisories GHSA-446w-rrm4-r47f GHSA-834c-x29c-f42c GHSA-934g-fvcc-4833 GHSA-phwm-87rg-27qq GHSA-x234-mg7q-m8g8 --- .../03/GHSA-446w-rrm4-r47f/GHSA-446w-rrm4-r47f.json | 3 ++- .../06/GHSA-834c-x29c-f42c/GHSA-834c-x29c-f42c.json | 6 +++++- .../06/GHSA-934g-fvcc-4833/GHSA-934g-fvcc-4833.json | 13 ++++++++----- .../06/GHSA-phwm-87rg-27qq/GHSA-phwm-87rg-27qq.json | 4 ++++ .../06/GHSA-x234-mg7q-m8g8/GHSA-x234-mg7q-m8g8.json | 4 ++++ 5 files changed, 23 insertions(+), 7 deletions(-) diff --git a/advisories/github-reviewed/2022/03/GHSA-446w-rrm4-r47f/GHSA-446w-rrm4-r47f.json b/advisories/github-reviewed/2022/03/GHSA-446w-rrm4-r47f/GHSA-446w-rrm4-r47f.json index 2485fc804d7..e0388adf7cd 100644 --- a/advisories/github-reviewed/2022/03/GHSA-446w-rrm4-r47f/GHSA-446w-rrm4-r47f.json +++ b/advisories/github-reviewed/2022/03/GHSA-446w-rrm4-r47f/GHSA-446w-rrm4-r47f.json @@ -59,7 +59,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": true, diff --git a/advisories/github-reviewed/2023/06/GHSA-834c-x29c-f42c/GHSA-834c-x29c-f42c.json b/advisories/github-reviewed/2023/06/GHSA-834c-x29c-f42c/GHSA-834c-x29c-f42c.json index 408052ca4e2..ee8b2d5f361 100644 --- a/advisories/github-reviewed/2023/06/GHSA-834c-x29c-f42c/GHSA-834c-x29c-f42c.json +++ b/advisories/github-reviewed/2023/06/GHSA-834c-x29c-f42c/GHSA-834c-x29c-f42c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-834c-x29c-f42c", - "modified": "2023-06-22T19:59:10Z", + "modified": "2023-06-27T18:38:25Z", "published": "2023-06-22T19:59:10Z", "aliases": [ "CVE-2023-35156" @@ -59,6 +59,10 @@ "type": "WEB", "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-834c-x29c-f42c" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35156" + }, { "type": "WEB", "url": "https://github.com/xwiki/xwiki-platform/commit/13875a6437d4525ac4aeea25918f2d2dffac9ee1" diff --git a/advisories/github-reviewed/2023/06/GHSA-934g-fvcc-4833/GHSA-934g-fvcc-4833.json b/advisories/github-reviewed/2023/06/GHSA-934g-fvcc-4833/GHSA-934g-fvcc-4833.json index b276840fa65..379031c8fbe 100644 --- a/advisories/github-reviewed/2023/06/GHSA-934g-fvcc-4833/GHSA-934g-fvcc-4833.json +++ b/advisories/github-reviewed/2023/06/GHSA-934g-fvcc-4833/GHSA-934g-fvcc-4833.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-934g-fvcc-4833", - "modified": "2023-06-16T20:27:35Z", + "modified": "2023-06-27T18:38:11Z", "published": "2023-06-16T18:30:33Z", "aliases": [ "CVE-2023-34659" @@ -9,7 +9,10 @@ "summary": "jeecg-boot SQL injection vulnerability", "details": "jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the `id` parameter of the `/jeecg-boot/jmreport/show` interface.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ { @@ -22,7 +25,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "0" + "introduced": "3.5.0" }, { "last_affected": "3.5.1" @@ -48,9 +51,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": "HIGH", + "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2023-06-16T20:27:35Z", "nvd_published_at": null diff --git a/advisories/github-reviewed/2023/06/GHSA-phwm-87rg-27qq/GHSA-phwm-87rg-27qq.json b/advisories/github-reviewed/2023/06/GHSA-phwm-87rg-27qq/GHSA-phwm-87rg-27qq.json index bdcbce614ab..800d26bda9a 100644 --- a/advisories/github-reviewed/2023/06/GHSA-phwm-87rg-27qq/GHSA-phwm-87rg-27qq.json +++ b/advisories/github-reviewed/2023/06/GHSA-phwm-87rg-27qq/GHSA-phwm-87rg-27qq.json @@ -59,6 +59,10 @@ "type": "WEB", "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-phwm-87rg-27qq" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35157" + }, { "type": "WEB", "url": "https://github.com/xwiki/xwiki-platform/commit/35e9073ffec567861e0abeea072bd97921a3decf" diff --git a/advisories/github-reviewed/2023/06/GHSA-x234-mg7q-m8g8/GHSA-x234-mg7q-m8g8.json b/advisories/github-reviewed/2023/06/GHSA-x234-mg7q-m8g8/GHSA-x234-mg7q-m8g8.json index 52e8ee85e69..23a8c6db325 100644 --- a/advisories/github-reviewed/2023/06/GHSA-x234-mg7q-m8g8/GHSA-x234-mg7q-m8g8.json +++ b/advisories/github-reviewed/2023/06/GHSA-x234-mg7q-m8g8/GHSA-x234-mg7q-m8g8.json @@ -59,6 +59,10 @@ "type": "WEB", "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-x234-mg7q-m8g8" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35159" + }, { "type": "WEB", "url": "https://github.com/xwiki/xwiki-platform/commit/5c20ff5e3bdea50f1053fe99a27e011b8d0e4b34"