diff --git a/advisories/github-reviewed/2022/05/GHSA-6j2v-g9rg-qcm5/GHSA-6j2v-g9rg-qcm5.json b/advisories/github-reviewed/2022/05/GHSA-6j2v-g9rg-qcm5/GHSA-6j2v-g9rg-qcm5.json new file mode 100644 index 00000000000..1c8e3248a36 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-6j2v-g9rg-qcm5/GHSA-6j2v-g9rg-qcm5.json @@ -0,0 +1,111 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j2v-g9rg-qcm5", + "modified": "2024-04-24T17:20:01Z", + "published": "2022-05-17T02:37:25Z", + "aliases": [ + "CVE-2016-6613" + ], + "summary": "phpMyAdmin Local file exposure through symlinks with UploadDir", + "details": "An issue was discovered in phpMyAdmin. A user can specially craft a symlink on disk, to a file which phpMyAdmin is permitted to read but the user is not, which phpMyAdmin will then expose to the user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.6" + }, + { + "fixed": "4.6.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.4" + }, + { + "fixed": "4.4.15.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.0" + }, + { + "fixed": "4.0.10.17" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-6613" + }, + { + "type": "PACKAGE", + "url": "https://github.com/phpmyadmin/composer" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/201701-32" + }, + { + "type": "WEB", + "url": "https://www.phpmyadmin.net/security/PMASA-2016-36" + }, + { + "type": "WEB", + "url": "http://www.securityfocus.com/bid/94115" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-24T17:20:01Z", + "nvd_published_at": "2016-12-11T02:59:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-7rf8-9r8f-qf59/GHSA-7rf8-9r8f-qf59.json b/advisories/github-reviewed/2022/05/GHSA-7rf8-9r8f-qf59/GHSA-7rf8-9r8f-qf59.json similarity index 67% rename from advisories/unreviewed/2022/05/GHSA-7rf8-9r8f-qf59/GHSA-7rf8-9r8f-qf59.json rename to advisories/github-reviewed/2022/05/GHSA-7rf8-9r8f-qf59/GHSA-7rf8-9r8f-qf59.json index fcfae38cd2e..cf268472f4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rf8-9r8f-qf59/GHSA-7rf8-9r8f-qf59.json +++ b/advisories/github-reviewed/2022/05/GHSA-7rf8-9r8f-qf59/GHSA-7rf8-9r8f-qf59.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7rf8-9r8f-qf59", - "modified": "2022-05-17T03:31:15Z", + "modified": "2024-04-24T17:21:07Z", "published": "2022-05-17T03:31:15Z", "aliases": [ "CVE-2016-2559" ], + "summary": "phpMyAdmin Cross-site scripting (XSS) vulnerability in SQL parser", "details": "Cross-site scripting (XSS) vulnerability in the format function in libraries/sql-parser/src/Utils/Error.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted query.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.5" + }, + { + "fixed": "4.5.5.1" + } + ] + } + ] + } ], "references": [ { @@ -25,6 +44,10 @@ "type": "WEB", "url": "https://github.com/phpmyadmin/phpmyadmin/commit/3a6a9a807d99371ee126635e1a505fc1fe0df32c" }, + { + "type": "PACKAGE", + "url": "https://github.com/phpmyadmin/composer" + }, { "type": "WEB", "url": "https://www.phpmyadmin.net/security/PMASA-2016-10" @@ -43,8 +66,8 @@ "CWE-79" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-24T17:21:07Z", "nvd_published_at": "2016-03-01T11:59:00Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-fcgm-62p3-f7cm/GHSA-fcgm-62p3-f7cm.json b/advisories/github-reviewed/2022/05/GHSA-fcgm-62p3-f7cm/GHSA-fcgm-62p3-f7cm.json new file mode 100644 index 00000000000..a1512b4d401 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-fcgm-62p3-f7cm/GHSA-fcgm-62p3-f7cm.json @@ -0,0 +1,111 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcgm-62p3-f7cm", + "modified": "2024-04-24T17:19:53Z", + "published": "2022-05-17T02:37:25Z", + "aliases": [ + "CVE-2016-6612" + ], + "summary": "phpMyAdmin Local file exposure", + "details": "An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.6" + }, + { + "fixed": "4.6.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.4" + }, + { + "fixed": "4.4.15.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.0" + }, + { + "fixed": "4.0.10.17" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-6612" + }, + { + "type": "PACKAGE", + "url": "https://github.com/phpmyadmin/composer" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/201701-32" + }, + { + "type": "WEB", + "url": "https://www.phpmyadmin.net/security/PMASA-2016-35" + }, + { + "type": "WEB", + "url": "http://www.securityfocus.com/bid/94113" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-24T17:19:53Z", + "nvd_published_at": "2016-12-11T02:59:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-phhm-63xx-v9rr/GHSA-phhm-63xx-v9rr.json b/advisories/github-reviewed/2022/05/GHSA-phhm-63xx-v9rr/GHSA-phhm-63xx-v9rr.json new file mode 100644 index 00000000000..d24a2041a21 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-phhm-63xx-v9rr/GHSA-phhm-63xx-v9rr.json @@ -0,0 +1,111 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phhm-63xx-v9rr", + "modified": "2024-04-24T17:19:11Z", + "published": "2022-05-17T02:37:14Z", + "aliases": [ + "CVE-2016-6628" + ], + "summary": "phpMyAdmin Reflected File Download attack", + "details": "An issue was discovered in phpMyAdmin. An attacker may be able to trigger a user to download a specially crafted malicious SVG file. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.6" + }, + { + "fixed": "4.6.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.4" + }, + { + "fixed": "4.4.15.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.0" + }, + { + "fixed": "4.0.10.17" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-6628" + }, + { + "type": "PACKAGE", + "url": "https://github.com/phpmyadmin/composer" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/201701-32" + }, + { + "type": "WEB", + "url": "https://www.phpmyadmin.net/security/PMASA-2016-51" + }, + { + "type": "WEB", + "url": "http://www.securityfocus.com/bid/92492" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-24T17:19:11Z", + "nvd_published_at": "2016-12-11T02:59:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-w8qg-j9fp-hrjf/GHSA-w8qg-j9fp-hrjf.json b/advisories/github-reviewed/2022/05/GHSA-w8qg-j9fp-hrjf/GHSA-w8qg-j9fp-hrjf.json similarity index 68% rename from advisories/unreviewed/2022/05/GHSA-w8qg-j9fp-hrjf/GHSA-w8qg-j9fp-hrjf.json rename to advisories/github-reviewed/2022/05/GHSA-w8qg-j9fp-hrjf/GHSA-w8qg-j9fp-hrjf.json index a9325c5a738..0d9c59f31ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8qg-j9fp-hrjf/GHSA-w8qg-j9fp-hrjf.json +++ b/advisories/github-reviewed/2022/05/GHSA-w8qg-j9fp-hrjf/GHSA-w8qg-j9fp-hrjf.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-w8qg-j9fp-hrjf", - "modified": "2022-05-17T03:31:14Z", + "modified": "2024-04-24T17:20:56Z", "published": "2022-05-17T03:31:14Z", "aliases": [ "CVE-2016-2562" ], + "summary": "phpMyAdmin Improper Input Validation", "details": "The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.5" + }, + { + "fixed": "4.5.5.1" + } + ] + } + ] + } ], "references": [ { @@ -25,6 +44,10 @@ "type": "WEB", "url": "https://github.com/phpmyadmin/phpmyadmin/commit/e42b7e3aedd29dd0f7a48575f20bfc5aca0ff976" }, + { + "type": "PACKAGE", + "url": "https://github.com/phpmyadmin/composer" + }, { "type": "WEB", "url": "https://www.phpmyadmin.net/security/PMASA-2016-13" @@ -43,8 +66,8 @@ "CWE-20" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-24T17:20:56Z", "nvd_published_at": "2016-03-01T11:59:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-6j2v-g9rg-qcm5/GHSA-6j2v-g9rg-qcm5.json b/advisories/unreviewed/2022/05/GHSA-6j2v-g9rg-qcm5/GHSA-6j2v-g9rg-qcm5.json deleted file mode 100644 index 83ce61a6727..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-6j2v-g9rg-qcm5/GHSA-6j2v-g9rg-qcm5.json +++ /dev/null @@ -1,50 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-6j2v-g9rg-qcm5", - "modified": "2022-05-17T02:37:25Z", - "published": "2022-05-17T02:37:25Z", - "aliases": [ - "CVE-2016-6613" - ], - "details": "An issue was discovered in phpMyAdmin. A user can specially craft a symlink on disk, to a file which phpMyAdmin is permitted to read but the user is not, which phpMyAdmin will then expose to the user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-6613" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html" - }, - { - "type": "WEB", - "url": "https://security.gentoo.org/glsa/201701-32" - }, - { - "type": "WEB", - "url": "https://www.phpmyadmin.net/security/PMASA-2016-36" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/94115" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-200" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2016-12-11T02:59:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-fcgm-62p3-f7cm/GHSA-fcgm-62p3-f7cm.json b/advisories/unreviewed/2022/05/GHSA-fcgm-62p3-f7cm/GHSA-fcgm-62p3-f7cm.json deleted file mode 100644 index b26deb54865..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-fcgm-62p3-f7cm/GHSA-fcgm-62p3-f7cm.json +++ /dev/null @@ -1,50 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-fcgm-62p3-f7cm", - "modified": "2022-05-17T02:37:25Z", - "published": "2022-05-17T02:37:25Z", - "aliases": [ - "CVE-2016-6612" - ], - "details": "An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-6612" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html" - }, - { - "type": "WEB", - "url": "https://security.gentoo.org/glsa/201701-32" - }, - { - "type": "WEB", - "url": "https://www.phpmyadmin.net/security/PMASA-2016-35" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/94113" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-200" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2016-12-11T02:59:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-phhm-63xx-v9rr/GHSA-phhm-63xx-v9rr.json b/advisories/unreviewed/2022/05/GHSA-phhm-63xx-v9rr/GHSA-phhm-63xx-v9rr.json deleted file mode 100644 index f673bcc0f70..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-phhm-63xx-v9rr/GHSA-phhm-63xx-v9rr.json +++ /dev/null @@ -1,50 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-phhm-63xx-v9rr", - "modified": "2022-05-17T02:37:14Z", - "published": "2022-05-17T02:37:14Z", - "aliases": [ - "CVE-2016-6628" - ], - "details": "An issue was discovered in phpMyAdmin. An attacker may be able to trigger a user to download a specially crafted malicious SVG file. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-6628" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html" - }, - { - "type": "WEB", - "url": "https://security.gentoo.org/glsa/201701-32" - }, - { - "type": "WEB", - "url": "https://www.phpmyadmin.net/security/PMASA-2016-51" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/92492" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2016-12-11T02:59:00Z" - } -} \ No newline at end of file