Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-12-04 05:11:29 +00:00
parent 964ef898a3
commit 6f0e45fda9
942 changed files with 1236 additions and 3708 deletions
@@ -3,14 +3,10 @@
"id": "GHSA-qc22-qwm9-j8rx",
"modified": "2021-12-20T16:57:06Z",
"published": "2021-12-20T16:59:31Z",
"aliases": [
],
"aliases": [],
"summary": "Remote Code Execution in npm-groovy-lint",
"details": "Versions of npm-groovy-lint prior to 9.1.0 bundle vulnerable versions of the Log4j library which are subject to remote code execution via jndi rendering. As a result npm-groovy-lint prior to 9.1.0 is also vulnerable.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -54,9 +54,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2022-11-22T18:57:13Z",
@@ -50,9 +50,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2022-11-22T18:57:24Z",
@@ -8,9 +8,7 @@
],
"summary": "Jenkins allows attackers to configure restricted projects",
"details": "Jenkins before 1.502 allows remote authenticated users to configure an otherwise restricted project via vectors related to post-build actions.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -78,9 +76,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-03-06T15:20:01Z",
@@ -50,9 +50,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2022-11-22T18:57:26Z",
@@ -54,9 +54,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2022-11-22T18:57:10Z",
@@ -8,9 +8,7 @@
],
"summary": "Apache Geronimo Application Server multiple directory traversal vulnerabilities",
"details": "Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group, (2) artifact, (3) version, or (4) fileType parameter to console/portal//Services/Repository (aka the Services/Repository portlet); the (5) createDB parameter to console/portal/Embedded DB/DB Manager (aka the Embedded DB/DB Manager portlet); or the (6) filename parameter to the createKeystore script in the Security/Keystores portlet.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -4,9 +4,7 @@
"modified": "2023-04-04T15:20:44Z",
"published": "2023-03-29T18:30:30Z",
"withdrawn": "2023-04-04T15:20:43Z",
"aliases": [
],
"aliases": [],
"summary": "Duplicate Advisory: pimcore is vulnerable to cross-site scripting in classes module",
"details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of [GHSA-4f25-2x2c-vg6v](https://github.com/advisories/GHSA-4f25-2x2c-vg6v). This link is maintained to preserve external references.\n\n## Original Description\nCross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-wqm8-jx8r-8rcq",
"modified": "2023-04-26T15:54:44Z",
"published": "2023-04-26T15:54:44Z",
"aliases": [
],
"aliases": [],
"summary": "Cross-site scripting vulnerabilities in old version of bundled TinyMCE",
"details": "An old version of TinyMCE include an XSS vulnerability, which was patched in a later version. This was described by TinyMCE:\n\n> A cross-site scripting (XSS) vulnerability was discovered in the core parser. The vulnerability allowed arbitrary JavaScript execution when inserting a specially crafted piece of content into the editor via the clipboard or APIs. This impacts all users who are using TinyMCE 4.9.10 or lower and TinyMCE 5.4.0 or lower.\n\nWe reviewed the potential impact of this vulnerability within the context of Silverstripe CMS. We concluded this is a medium impact vulnerability given how TinyMCE is used by Silverstripe CMS.\n\nReported by: Developers at ACC",
"severity": [
@@ -62,9 +60,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2023-04-26T15:54:44Z",
@@ -4,9 +4,7 @@
"modified": "2024-02-07T18:20:22Z",
"published": "2023-11-16T15:30:20Z",
"withdrawn": "2024-02-07T18:20:22Z",
"aliases": [
],
"aliases": [],
"summary": "Duplicate Advisory: CKEditor Cross-site Scripting vulnerability",
"details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-wh5w-82f3-wrxh. This link is maintained to preserve external references.\n\n## Original Description\nA Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /`ckeditor/samples/old/ajax.html` file and retrieve an authorized user's information.",
"severity": [
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
@@ -3,9 +3,7 @@
"id": "GHSA-879p-8gw4-mcpw",
"modified": "2024-03-15T19:01:10Z",
"published": "2024-03-15T19:01:10Z",
"aliases": [
],
"aliases": [],
"summary": " fgr Vulnerable to Insecure Default Variable Initialization",
"details": "### Impact\nAny users whom would not desire a traceback to be included in their logs whenever an error is raised in their code will be affected.\n\nIf users have inadvertently created a scenario in their code that could cause a traceback to include sensitive information _and_ a malicious entity gained access to their log stream, this could create an issue.\n\n### Patches\nNone yet... users will need to upgrade to `0.4.*`\n\n### Workarounds\nNo particularly reasonable ones at present.\n\n### References\n* https://cwe.mitre.org/data/definitions/453.html\n* https://www.invicti.com/web-vulnerability-scanner/vulnerabilities/stack-trace-disclosure-python/",
"severity": [
@@ -8,9 +8,7 @@
],
"summary": "Bagisto vulnerable to Insecure Direct Object Reference (IDOR)",
"details": "Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.0 allows an attacker to obtain sensitive information via the invoice ID parameter.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -55,9 +53,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-03-15T21:03:01Z",
File diff suppressed because one or more lines are too long
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",

Some files were not shown because too many files have changed in this diff Show More