From 7c7800a9fb19ec31b403c9e2e81d331f419379c4 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 24 Apr 2024 17:21:37 +0000 Subject: [PATCH] Publish Advisories GHSA-6j2v-g9rg-qcm5 GHSA-7rf8-9r8f-qf59 GHSA-fcgm-62p3-f7cm GHSA-phhm-63xx-v9rr GHSA-w8qg-j9fp-hrjf GHSA-6j2v-g9rg-qcm5 GHSA-fcgm-62p3-f7cm GHSA-phhm-63xx-v9rr --- .../GHSA-6j2v-g9rg-qcm5.json | 111 ++++++++++++++++++ .../GHSA-7rf8-9r8f-qf59.json | 31 ++++- .../GHSA-fcgm-62p3-f7cm.json | 111 ++++++++++++++++++ .../GHSA-phhm-63xx-v9rr.json | 111 ++++++++++++++++++ .../GHSA-w8qg-j9fp-hrjf.json | 31 ++++- .../GHSA-6j2v-g9rg-qcm5.json | 50 -------- .../GHSA-fcgm-62p3-f7cm.json | 50 -------- .../GHSA-phhm-63xx-v9rr.json | 50 -------- 8 files changed, 387 insertions(+), 158 deletions(-) create mode 100644 advisories/github-reviewed/2022/05/GHSA-6j2v-g9rg-qcm5/GHSA-6j2v-g9rg-qcm5.json rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-7rf8-9r8f-qf59/GHSA-7rf8-9r8f-qf59.json (67%) create mode 100644 advisories/github-reviewed/2022/05/GHSA-fcgm-62p3-f7cm/GHSA-fcgm-62p3-f7cm.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-phhm-63xx-v9rr/GHSA-phhm-63xx-v9rr.json rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-w8qg-j9fp-hrjf/GHSA-w8qg-j9fp-hrjf.json (68%) delete mode 100644 advisories/unreviewed/2022/05/GHSA-6j2v-g9rg-qcm5/GHSA-6j2v-g9rg-qcm5.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-fcgm-62p3-f7cm/GHSA-fcgm-62p3-f7cm.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-phhm-63xx-v9rr/GHSA-phhm-63xx-v9rr.json diff --git a/advisories/github-reviewed/2022/05/GHSA-6j2v-g9rg-qcm5/GHSA-6j2v-g9rg-qcm5.json b/advisories/github-reviewed/2022/05/GHSA-6j2v-g9rg-qcm5/GHSA-6j2v-g9rg-qcm5.json new file mode 100644 index 00000000000..1c8e3248a36 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-6j2v-g9rg-qcm5/GHSA-6j2v-g9rg-qcm5.json @@ -0,0 +1,111 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j2v-g9rg-qcm5", + "modified": "2024-04-24T17:20:01Z", + "published": "2022-05-17T02:37:25Z", + "aliases": [ + "CVE-2016-6613" + ], + "summary": "phpMyAdmin Local file exposure through symlinks with UploadDir", + "details": "An issue was discovered in phpMyAdmin. A user can specially craft a symlink on disk, to a file which phpMyAdmin is permitted to read but the user is not, which phpMyAdmin will then expose to the user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.6" + }, + { + "fixed": "4.6.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.4" + }, + { + "fixed": "4.4.15.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.0" + }, + { + "fixed": "4.0.10.17" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-6613" + }, + { + "type": "PACKAGE", + "url": "https://github.com/phpmyadmin/composer" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/201701-32" + }, + { + "type": "WEB", + "url": "https://www.phpmyadmin.net/security/PMASA-2016-36" + }, + { + "type": "WEB", + "url": "http://www.securityfocus.com/bid/94115" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-24T17:20:01Z", + "nvd_published_at": "2016-12-11T02:59:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-7rf8-9r8f-qf59/GHSA-7rf8-9r8f-qf59.json b/advisories/github-reviewed/2022/05/GHSA-7rf8-9r8f-qf59/GHSA-7rf8-9r8f-qf59.json similarity index 67% rename from advisories/unreviewed/2022/05/GHSA-7rf8-9r8f-qf59/GHSA-7rf8-9r8f-qf59.json rename to advisories/github-reviewed/2022/05/GHSA-7rf8-9r8f-qf59/GHSA-7rf8-9r8f-qf59.json index fcfae38cd2e..cf268472f4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rf8-9r8f-qf59/GHSA-7rf8-9r8f-qf59.json +++ b/advisories/github-reviewed/2022/05/GHSA-7rf8-9r8f-qf59/GHSA-7rf8-9r8f-qf59.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7rf8-9r8f-qf59", - "modified": "2022-05-17T03:31:15Z", + "modified": "2024-04-24T17:21:07Z", "published": "2022-05-17T03:31:15Z", "aliases": [ "CVE-2016-2559" ], + "summary": "phpMyAdmin Cross-site scripting (XSS) vulnerability in SQL parser", "details": "Cross-site scripting (XSS) vulnerability in the format function in libraries/sql-parser/src/Utils/Error.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted query.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.5" + }, + { + "fixed": "4.5.5.1" + } + ] + } + ] + } ], "references": [ { @@ -25,6 +44,10 @@ "type": "WEB", "url": "https://github.com/phpmyadmin/phpmyadmin/commit/3a6a9a807d99371ee126635e1a505fc1fe0df32c" }, + { + "type": "PACKAGE", + "url": "https://github.com/phpmyadmin/composer" + }, { "type": "WEB", "url": "https://www.phpmyadmin.net/security/PMASA-2016-10" @@ -43,8 +66,8 @@ "CWE-79" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-24T17:21:07Z", "nvd_published_at": "2016-03-01T11:59:00Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-fcgm-62p3-f7cm/GHSA-fcgm-62p3-f7cm.json b/advisories/github-reviewed/2022/05/GHSA-fcgm-62p3-f7cm/GHSA-fcgm-62p3-f7cm.json new file mode 100644 index 00000000000..a1512b4d401 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-fcgm-62p3-f7cm/GHSA-fcgm-62p3-f7cm.json @@ -0,0 +1,111 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcgm-62p3-f7cm", + "modified": "2024-04-24T17:19:53Z", + "published": "2022-05-17T02:37:25Z", + "aliases": [ + "CVE-2016-6612" + ], + "summary": "phpMyAdmin Local file exposure", + "details": "An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.6" + }, + { + "fixed": "4.6.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.4" + }, + { + "fixed": "4.4.15.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.0" + }, + { + "fixed": "4.0.10.17" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-6612" + }, + { + "type": "PACKAGE", + "url": "https://github.com/phpmyadmin/composer" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/201701-32" + }, + { + "type": "WEB", + "url": "https://www.phpmyadmin.net/security/PMASA-2016-35" + }, + { + "type": "WEB", + "url": "http://www.securityfocus.com/bid/94113" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-24T17:19:53Z", + "nvd_published_at": "2016-12-11T02:59:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-phhm-63xx-v9rr/GHSA-phhm-63xx-v9rr.json b/advisories/github-reviewed/2022/05/GHSA-phhm-63xx-v9rr/GHSA-phhm-63xx-v9rr.json new file mode 100644 index 00000000000..d24a2041a21 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-phhm-63xx-v9rr/GHSA-phhm-63xx-v9rr.json @@ -0,0 +1,111 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phhm-63xx-v9rr", + "modified": "2024-04-24T17:19:11Z", + "published": "2022-05-17T02:37:14Z", + "aliases": [ + "CVE-2016-6628" + ], + "summary": "phpMyAdmin Reflected File Download attack", + "details": "An issue was discovered in phpMyAdmin. An attacker may be able to trigger a user to download a specially crafted malicious SVG file. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.6" + }, + { + "fixed": "4.6.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.4" + }, + { + "fixed": "4.4.15.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.0" + }, + { + "fixed": "4.0.10.17" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-6628" + }, + { + "type": "PACKAGE", + "url": "https://github.com/phpmyadmin/composer" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/201701-32" + }, + { + "type": "WEB", + "url": "https://www.phpmyadmin.net/security/PMASA-2016-51" + }, + { + "type": "WEB", + "url": "http://www.securityfocus.com/bid/92492" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-24T17:19:11Z", + "nvd_published_at": "2016-12-11T02:59:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-w8qg-j9fp-hrjf/GHSA-w8qg-j9fp-hrjf.json b/advisories/github-reviewed/2022/05/GHSA-w8qg-j9fp-hrjf/GHSA-w8qg-j9fp-hrjf.json similarity index 68% rename from advisories/unreviewed/2022/05/GHSA-w8qg-j9fp-hrjf/GHSA-w8qg-j9fp-hrjf.json rename to advisories/github-reviewed/2022/05/GHSA-w8qg-j9fp-hrjf/GHSA-w8qg-j9fp-hrjf.json index a9325c5a738..0d9c59f31ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8qg-j9fp-hrjf/GHSA-w8qg-j9fp-hrjf.json +++ b/advisories/github-reviewed/2022/05/GHSA-w8qg-j9fp-hrjf/GHSA-w8qg-j9fp-hrjf.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-w8qg-j9fp-hrjf", - "modified": "2022-05-17T03:31:14Z", + "modified": "2024-04-24T17:20:56Z", "published": "2022-05-17T03:31:14Z", "aliases": [ "CVE-2016-2562" ], + "summary": "phpMyAdmin Improper Input Validation", "details": "The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.5" + }, + { + "fixed": "4.5.5.1" + } + ] + } + ] + } ], "references": [ { @@ -25,6 +44,10 @@ "type": "WEB", "url": "https://github.com/phpmyadmin/phpmyadmin/commit/e42b7e3aedd29dd0f7a48575f20bfc5aca0ff976" }, + { + "type": "PACKAGE", + "url": "https://github.com/phpmyadmin/composer" + }, { "type": "WEB", "url": "https://www.phpmyadmin.net/security/PMASA-2016-13" @@ -43,8 +66,8 @@ "CWE-20" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-24T17:20:56Z", "nvd_published_at": "2016-03-01T11:59:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-6j2v-g9rg-qcm5/GHSA-6j2v-g9rg-qcm5.json b/advisories/unreviewed/2022/05/GHSA-6j2v-g9rg-qcm5/GHSA-6j2v-g9rg-qcm5.json deleted file mode 100644 index 83ce61a6727..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-6j2v-g9rg-qcm5/GHSA-6j2v-g9rg-qcm5.json +++ /dev/null @@ -1,50 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-6j2v-g9rg-qcm5", - "modified": "2022-05-17T02:37:25Z", - "published": "2022-05-17T02:37:25Z", - "aliases": [ - "CVE-2016-6613" - ], - "details": "An issue was discovered in phpMyAdmin. A user can specially craft a symlink on disk, to a file which phpMyAdmin is permitted to read but the user is not, which phpMyAdmin will then expose to the user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-6613" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html" - }, - { - "type": "WEB", - "url": "https://security.gentoo.org/glsa/201701-32" - }, - { - "type": "WEB", - "url": "https://www.phpmyadmin.net/security/PMASA-2016-36" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/94115" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-200" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2016-12-11T02:59:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-fcgm-62p3-f7cm/GHSA-fcgm-62p3-f7cm.json b/advisories/unreviewed/2022/05/GHSA-fcgm-62p3-f7cm/GHSA-fcgm-62p3-f7cm.json deleted file mode 100644 index b26deb54865..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-fcgm-62p3-f7cm/GHSA-fcgm-62p3-f7cm.json +++ /dev/null @@ -1,50 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-fcgm-62p3-f7cm", - "modified": "2022-05-17T02:37:25Z", - "published": "2022-05-17T02:37:25Z", - "aliases": [ - "CVE-2016-6612" - ], - "details": "An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-6612" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html" - }, - { - "type": "WEB", - "url": "https://security.gentoo.org/glsa/201701-32" - }, - { - "type": "WEB", - "url": "https://www.phpmyadmin.net/security/PMASA-2016-35" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/94113" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-200" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2016-12-11T02:59:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-phhm-63xx-v9rr/GHSA-phhm-63xx-v9rr.json b/advisories/unreviewed/2022/05/GHSA-phhm-63xx-v9rr/GHSA-phhm-63xx-v9rr.json deleted file mode 100644 index f673bcc0f70..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-phhm-63xx-v9rr/GHSA-phhm-63xx-v9rr.json +++ /dev/null @@ -1,50 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-phhm-63xx-v9rr", - "modified": "2022-05-17T02:37:14Z", - "published": "2022-05-17T02:37:14Z", - "aliases": [ - "CVE-2016-6628" - ], - "details": "An issue was discovered in phpMyAdmin. An attacker may be able to trigger a user to download a specially crafted malicious SVG file. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-6628" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html" - }, - { - "type": "WEB", - "url": "https://security.gentoo.org/glsa/201701-32" - }, - { - "type": "WEB", - "url": "https://www.phpmyadmin.net/security/PMASA-2016-51" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/92492" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2016-12-11T02:59:00Z" - } -} \ No newline at end of file