diff --git a/advisories/github-reviewed/2020/06/GHSA-ffvq-7w96-97p7/GHSA-ffvq-7w96-97p7.json b/advisories/github-reviewed/2020/06/GHSA-ffvq-7w96-97p7/GHSA-ffvq-7w96-97p7.json index 03936870a11..ac6c397ead1 100644 --- a/advisories/github-reviewed/2020/06/GHSA-ffvq-7w96-97p7/GHSA-ffvq-7w96-97p7.json +++ b/advisories/github-reviewed/2020/06/GHSA-ffvq-7w96-97p7/GHSA-ffvq-7w96-97p7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ffvq-7w96-97p7", - "modified": "2021-01-14T21:29:27Z", + "modified": "2024-06-05T17:09:52Z", "published": "2020-06-15T19:34:50Z", "aliases": [ "CVE-2018-15756" @@ -25,10 +25,10 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "5.1" + "introduced": "5.1.0.RELEASE" }, { - "fixed": "5.1.1" + "fixed": "5.1.1.RELEASE" } ] } @@ -44,10 +44,10 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "5.0" + "introduced": "5.0.0.RELEASE" }, { - "fixed": "5.0.10" + "fixed": "5.0.10.RELEASE" } ] } @@ -63,10 +63,10 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "0" + "introduced": "4.2.0.RELEASE" }, { - "fixed": "4.3.20" + "fixed": "4.3.20.RELEASE" } ] } @@ -158,6 +158,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread.html/339fd112517e4873695b5115b96acdddbfc8f83b10598528d37c7d12@%3Cissues.activemq.apache.org%3E" }, + { + "type": "PACKAGE", + "url": "https://github.com/spring-projects/spring-framework" + }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/105703" diff --git a/advisories/github-reviewed/2024/06/GHSA-g9rv-6g56-65h8/GHSA-g9rv-6g56-65h8.json b/advisories/github-reviewed/2024/06/GHSA-g9rv-6g56-65h8/GHSA-g9rv-6g56-65h8.json new file mode 100644 index 00000000000..c6b86257ffe --- /dev/null +++ b/advisories/github-reviewed/2024/06/GHSA-g9rv-6g56-65h8/GHSA-g9rv-6g56-65h8.json @@ -0,0 +1,77 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9rv-6g56-65h8", + "modified": "2024-06-05T17:10:38Z", + "published": "2024-06-05T17:10:38Z", + "aliases": [ + + ], + "summary": "Typo3 Security Misconfiguration in User Session Handling", + "details": "When users change their password existing sessions for that particular user account are not revoked. A valid backend or frontend user account is required in order to make use of this vulnerability.", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.0.0" + }, + { + "fixed": "8.7.25" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.0.0" + }, + { + "fixed": "9.5.6" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/2019-05-07-2.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/TYPO3/typo3" + }, + { + "type": "WEB", + "url": "https://typo3.org/security/advisory/typo3-core-sa-2019-011" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-06-05T17:10:38Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/06/GHSA-m96r-7vqm-j95g/GHSA-m96r-7vqm-j95g.json b/advisories/github-reviewed/2024/06/GHSA-m96r-7vqm-j95g/GHSA-m96r-7vqm-j95g.json new file mode 100644 index 00000000000..aba6a70e5af --- /dev/null +++ b/advisories/github-reviewed/2024/06/GHSA-m96r-7vqm-j95g/GHSA-m96r-7vqm-j95g.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m96r-7vqm-j95g", + "modified": "2024-06-05T17:09:30Z", + "published": "2024-06-05T17:09:30Z", + "aliases": [ + + ], + "summary": "Typo3 Information Disclosure in User Authentication", + "details": "It has been discovered that login failures have been logged on the default stream with log level \"warning\" including plain-text user credentials.", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.0.0" + }, + { + "fixed": "9.5.6" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/2019-05-07-5.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/TYPO3/typo3" + }, + { + "type": "WEB", + "url": "https://typo3.org/security/advisory/typo3-core-sa-2019-010" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-06-05T17:09:30Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/06/GHSA-q9c4-9v5m-597p/GHSA-q9c4-9v5m-597p.json b/advisories/github-reviewed/2024/06/GHSA-q9c4-9v5m-597p/GHSA-q9c4-9v5m-597p.json new file mode 100644 index 00000000000..06233335a7f --- /dev/null +++ b/advisories/github-reviewed/2024/06/GHSA-q9c4-9v5m-597p/GHSA-q9c4-9v5m-597p.json @@ -0,0 +1,77 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9c4-9v5m-597p", + "modified": "2024-06-05T17:10:08Z", + "published": "2024-06-05T17:10:08Z", + "aliases": [ + + ], + "summary": "Typo3 Information Disclosure in Backend User Interface", + "details": "The element information component used to display properties of a certain record is susceptible to information disclosure. The list of references from or to the record is not properly checked for the backend user’s permissions. A valid backend user account is needed in order to exploit this vulnerability.", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.0.0" + }, + { + "fixed": "8.7.27" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.0.0" + }, + { + "fixed": "9.5.8" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/2019-06-25-1.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/TYPO3/typo3" + }, + { + "type": "WEB", + "url": "https://typo3.org/security/advisory/typo3-core-sa-2019-014" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-06-05T17:10:08Z", + "nvd_published_at": null + } +} \ No newline at end of file