From a3a270543d7ed912d90e00fa64360dfb7ebd4efd Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 25 Apr 2024 23:16:10 +0000 Subject: [PATCH] Publish Advisories GHSA-4r6g-xhx7-fm36 GHSA-j99g-qjvx-995g GHSA-4r6g-xhx7-fm36 GHSA-j99g-qjvx-995g --- .../GHSA-4r6g-xhx7-fm36.json | 96 +++++++++++++++++++ .../GHSA-j99g-qjvx-995g.json | 93 ++++++++++++++++++ .../GHSA-4r6g-xhx7-fm36.json | 46 --------- .../GHSA-j99g-qjvx-995g.json | 42 -------- 4 files changed, 189 insertions(+), 88 deletions(-) create mode 100644 advisories/github-reviewed/2022/05/GHSA-4r6g-xhx7-fm36/GHSA-4r6g-xhx7-fm36.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-j99g-qjvx-995g/GHSA-j99g-qjvx-995g.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-4r6g-xhx7-fm36/GHSA-4r6g-xhx7-fm36.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-j99g-qjvx-995g/GHSA-j99g-qjvx-995g.json diff --git a/advisories/github-reviewed/2022/05/GHSA-4r6g-xhx7-fm36/GHSA-4r6g-xhx7-fm36.json b/advisories/github-reviewed/2022/05/GHSA-4r6g-xhx7-fm36/GHSA-4r6g-xhx7-fm36.json new file mode 100644 index 00000000000..d8870aff8ec --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-4r6g-xhx7-fm36/GHSA-4r6g-xhx7-fm36.json @@ -0,0 +1,96 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r6g-xhx7-fm36", + "modified": "2024-04-25T23:15:43Z", + "published": "2022-05-17T02:42:22Z", + "aliases": [ + "CVE-2015-0269" + ], + "summary": "Contao Core directory traversal vulnerability", + "details": "Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated backend users to view files outside their file mounts or the document root via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "contao/core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.4.0" + }, + { + "fixed": "3.4.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "contao/core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.0.0" + }, + { + "fixed": "3.2.19" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-0269" + }, + { + "type": "WEB", + "url": "https://github.com/contao/core/commit/0229e839b4849e402256b972eb62f89f2c29674d" + }, + { + "type": "WEB", + "url": "https://contao.org/en/news/contao-3_2_19.html" + }, + { + "type": "WEB", + "url": "https://contao.org/en/news/contao-3_4_4.html" + }, + { + "type": "WEB", + "url": "https://contao.org/en/news/directory-traversal-vulnerability-cve-2015-0269.html" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core/CVE-2015-0269.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/contao/core" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-25T23:15:43Z", + "nvd_published_at": "2017-05-26T17:29:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-j99g-qjvx-995g/GHSA-j99g-qjvx-995g.json b/advisories/github-reviewed/2022/05/GHSA-j99g-qjvx-995g/GHSA-j99g-qjvx-995g.json new file mode 100644 index 00000000000..0ad6362046c --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-j99g-qjvx-995g/GHSA-j99g-qjvx-995g.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j99g-qjvx-995g", + "modified": "2024-04-25T23:15:07Z", + "published": "2022-05-13T01:07:57Z", + "aliases": [ + "CVE-2019-10643" + ], + "summary": "Contao Does Not Expire Tokens Correctly", + "details": "Security researcher Ali Razzaq has discovered that confirming an opt-in token does not invalidate previous opt-in tokens in Contao 4.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "contao/contao" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.7.0" + }, + { + "fixed": "4.7.3" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "contao/core-bundle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.7.0" + }, + { + "fixed": "4.7.3" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-10643" + }, + { + "type": "WEB", + "url": "https://github.com/contao/contao/commit/70348cc812b110831ad66a4f9857883f75649b88" + }, + { + "type": "WEB", + "url": "https://contao.org/en/news.html" + }, + { + "type": "WEB", + "url": "https://contao.org/en/news/security-vulnerability-cve-2019-10643.html" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/contao/CVE-2019-10643.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core-bundle/CVE-2019-10643.yaml" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287", + "CWE-324" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-25T23:15:07Z", + "nvd_published_at": "2019-04-17T19:29:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-4r6g-xhx7-fm36/GHSA-4r6g-xhx7-fm36.json b/advisories/unreviewed/2022/05/GHSA-4r6g-xhx7-fm36/GHSA-4r6g-xhx7-fm36.json deleted file mode 100644 index 79b9160a238..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-4r6g-xhx7-fm36/GHSA-4r6g-xhx7-fm36.json +++ /dev/null @@ -1,46 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-4r6g-xhx7-fm36", - "modified": "2022-05-17T02:42:22Z", - "published": "2022-05-17T02:42:22Z", - "aliases": [ - "CVE-2015-0269" - ], - "details": "Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated \"back end\" users to view files outside their file mounts or the document root via unspecified vectors.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-0269" - }, - { - "type": "WEB", - "url": "https://contao.org/en/news/contao-3_2_19.html" - }, - { - "type": "WEB", - "url": "https://contao.org/en/news/contao-3_4_4.html" - }, - { - "type": "WEB", - "url": "https://contao.org/en/news/directory-traversal-vulnerability-cve-2015-0269.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-22" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2017-05-26T17:29:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-j99g-qjvx-995g/GHSA-j99g-qjvx-995g.json b/advisories/unreviewed/2022/05/GHSA-j99g-qjvx-995g/GHSA-j99g-qjvx-995g.json deleted file mode 100644 index 2356ba2b73c..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-j99g-qjvx-995g/GHSA-j99g-qjvx-995g.json +++ /dev/null @@ -1,42 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-j99g-qjvx-995g", - "modified": "2022-05-13T01:07:57Z", - "published": "2022-05-13T01:07:57Z", - "aliases": [ - "CVE-2019-10643" - ], - "details": "Contao 4.7 allows Use of a Key Past its Expiration Date.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-10643" - }, - { - "type": "WEB", - "url": "https://contao.org/en/news.html" - }, - { - "type": "WEB", - "url": "https://contao.org/en/news/security-vulnerability-cve-2019-10643.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-287" - ], - "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2019-04-17T19:29:00Z" - } -} \ No newline at end of file