diff --git a/advisories/github-reviewed/2025/05/GHSA-f6rx-hf55-4255/GHSA-f6rx-hf55-4255.json b/advisories/github-reviewed/2025/05/GHSA-f6rx-hf55-4255/GHSA-f6rx-hf55-4255.json new file mode 100644 index 00000000000..829fa8ec163 --- /dev/null +++ b/advisories/github-reviewed/2025/05/GHSA-f6rx-hf55-4255/GHSA-f6rx-hf55-4255.json @@ -0,0 +1,107 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6rx-hf55-4255", + "modified": "2025-05-15T16:08:02Z", + "published": "2025-05-15T16:08:02Z", + "aliases": [ + "CVE-2025-47778" + ], + "summary": "Sulu vulnerable to XXE in SVG File upload Inspector", + "details": "### Impact\n\nA admin user can upload SVG which may load external data via XML DOM library, specially this can be used for eventually reference none secure XML External Entity References.\n\n### Patches\n\nThe problem has not been patched yet. Users should upgrade to patched versions once they become available. Currently affected versions are:\n\n - 2.6.9\n - 2.5.25\n - 3.0.0-alpha3\n\n### Workarounds\n\nPatch the effect file `src/Sulu/Bundle/MediaBundle/FileInspector/SvgFileInspector.php` in sulu with:\n\n```diff\n-$dom->loadXML($svg, \\LIBXML_NOENT | \\LIBXML_DTDLOAD);\n+$dom->loadXML($data, LIBXML_NONET);\n```\n\n### References\n\n - GitHub repository: https://github.com/sulu/sulu\n - Vulnerable code: https://github.com/sulu/sulu/blob/2.6/src/Sulu/Bundle/MediaBundle/FileInspector/SvgFileInspector.php", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "sulu/sulu" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.5.21" + }, + { + "fixed": "2.5.25" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "sulu/sulu" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.6.5" + }, + { + "fixed": "2.6.9" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "sulu/sulu" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.0.0-alpha1" + }, + { + "fixed": "3.0.0-alpha3" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/sulu/sulu/security/advisories/GHSA-f6rx-hf55-4255" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47778" + }, + { + "type": "WEB", + "url": "https://github.com/sulu/sulu/commit/02f52fca04eb9495b9b4a0c5cc64cf23bc27f544" + }, + { + "type": "PACKAGE", + "url": "https://github.com/sulu/sulu" + }, + { + "type": "WEB", + "url": "https://github.com/sulu/sulu/blob/2.6/src/Sulu/Bundle/MediaBundle/FileInspector/SvgFileInspector.php" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-05-15T16:08:02Z", + "nvd_published_at": "2025-05-14T16:15:29Z" + } +} \ No newline at end of file