Publish Advisories

GHSA-f8pg-wp5j-rjxx
GHSA-m2vv-5vj5-2hm7
This commit is contained in:
advisory-database[bot]
2024-10-11 20:46:25 +00:00
parent 01e94decbd
commit 83c74eae41
2 changed files with 29 additions and 6 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f8pg-wp5j-rjxx",
"modified": "2023-08-29T21:35:55Z",
"modified": "2024-10-11T20:45:57Z",
"published": "2022-05-17T04:32:26Z",
"aliases": [
"CVE-2012-5491"
@@ -9,13 +9,20 @@
"summary": "Plone Information Disclosure",
"details": "`z3c.form`, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain the default form field values by leveraging knowledge of the form location and the element id.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
}
],
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "plone"
"name": "Plone"
},
"ranges": [
{
@@ -34,14 +41,14 @@
{
"package": {
"ecosystem": "PyPI",
"name": "plone"
"name": "Plone"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.3a1"
"introduced": "4.3a0"
},
{
"fixed": "4.3b1"
@@ -56,10 +63,18 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2012-5491"
},
{
"type": "PACKAGE",
"url": "https://github.com/plone/Plone"
},
{
"type": "WEB",
"url": "https://github.com/plone/Products.CMFPlone/blob/4.2.3/docs/CHANGES.txt"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2014-33.yaml"
},
{
"type": "WEB",
"url": "https://plone.org/products/plone-hotfix/releases/20121106"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m2vv-5vj5-2hm7",
"modified": "2022-11-22T00:14:54Z",
"modified": "2024-10-11T20:44:44Z",
"published": "2022-11-14T12:00:15Z",
"aliases": [
"CVE-2022-45198"
@@ -12,6 +12,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
}
],
"affected": [
@@ -60,6 +64,10 @@
"type": "WEB",
"url": "https://cwe.mitre.org/data/definitions/409.html"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2022-42979.yaml"
},
{
"type": "WEB",
"url": "https://github.com/python-pillow/Pillow"